packetstormsecurity.com
http://packetstormsecurity.com/files/157565/TrixBox-CE-2.8.0.4-Command-Execution.html CVE-2020-7351
HIGH
Fonality Trixbox CE Post-Authentication Command Injection
Record summary
CVE-2020-7351 has a selected CVSS score of 7.3 (high); EIP currently links 1 catalogued exploit.
Description
An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects: Fonality Trixbox Community Edition, versions 1.2.0 through 2.8.0.4. Versions 1.0 and 1.1 are unaffected.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Trixbox Community EditionBrowse Fonality / Trixbox Community Edition | CVE List | 1.0 | unaffected |
| 1.1 | unaffected | ||
| 2.8.0.4 to ≤ 2.8.0.4 | affected |
Proofs of concept
1Catalogued exploits
MetasploitTrixBox CE endpoint_devicemap.php Authenticated Command ExecutionMetasploit exploitby Anastasios Stasinopoulos ( <Anastasios Stasinopoulos (@ancst)>Not analyzed1 file
References
3github.com
https://github.com/rapid7/metasploit-framework/pull/13353 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-7351