Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in the extension parameter in an OriginateVDRelogin action to manager_send.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
VICIDIAL dialer 输入验证漏洞
Vulnerability Description
VICIDIAL dialer(又名Asterisk GUI client)是美国Vicidial集团所负责维护的一套基于Asterisk的开源PBX系统,也是一个用于处理大量呼入、呼出的呼叫中心软件包。 VICIDIAL dialer 2.8-403a及之前的版本和2.7,及2.7RC1版本中存在安全漏洞。当执行OriginateVDRelogin操作时,远程攻击者可借助manager_send.php脚本的extension参数中的shell元字符利用该漏洞执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A