E19-7qmt1
CVSS:
9.0 (AV:N/AC:L/Au:S/C:C/I:C/A:C)
False Positive:
t
Variants:
1
Year:
2019
Description
An OS command injection exists in FusionPBX 4.4.8 due to lack of parameter sanitization while parsing requests to service edit.php. By exploiting this flaw, an authenticated remote attacker can run arbitrary OS commands on the target system.
CVE
References
MSB
BID
ExploitDB
Secunia
Security Tracker
Metasploit
ZDI
OSVDB
{}