FreePBX(前称Asterisk Management Portal)是FreePBX项目的一套通过GUI(基于网页的图形化接口)配置Asterisk(IP电话系统)的工具。 FreePBX存在安全漏洞,该漏洞源于从官方 ISO 镜像安装期间,在 Asterisk 全局变量列表中添加 AMPDBUSER、AMPDBPASS、AMPMGRUSER、AMPMGRPASS 变量,这些变量会公开 Asterisk 数据库的明文身份验证凭据(MariaDB/ MySQL) 和 Asterisk Manager接
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-2294 | 3.5 LOW | UCMS Column Configuration saddpost.php cross site scripting |
| CVE-2023-30212 | OURPHP 跨站脚本漏洞 | |
| CVE-2023-24796 | Vinga WR-AC1200 安全漏洞 | |
| CVE-2022-39989 | Fighting Cock Information System 信任管理问题漏洞 | |
| CVE-2023-30112 | Medicine Tracker System SQL注入漏洞 | |
| CVE-2023-30265 | CLTPHP 路径遍历漏洞 | |
| CVE-2023-30266 | CLTPHP 代码问题漏洞 | |
| CVE-2023-30267 | CLTPHP 跨站脚本漏洞 | |
| CVE-2023-30269 | CLTPHP 输入验证错误漏洞 | |
| CVE-2022-27978 | ToolJet 安全漏洞 | |
| CVE-2022-27979 | ToolJet 跨站脚本漏洞 | |
| CVE-2023-30210 | OURPHP 跨站脚本漏洞 | |
| CVE-2023-30211 | OURPHP SQL注入漏洞 | |
| CVE-2023-27107 | MyQ Solution Print Server和MyQ Solution Central Server 安全漏洞 | |
| CVE-2022-44232 | libming 安全漏洞 | |
| CVE-2023-26930 | Glyph & Cog XpdfReader 安全漏洞 | |
| CVE-2020-36070 | Voyager 安全漏洞 | |
| CVE-2023-29596 | Cmix 安全漏洞 | |
| CVE-2023-29835 | Wondershare Dr.Fone 安全漏洞 | |
| CVE-2023-29836 | Exelysis Unified Communication Solutions 跨站脚本漏洞 |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet