FusionPBX 5.6.5 及之前版本在 函数中存在操作系统命令注入漏洞。攻击者无需身份验证即可通过拨打带有恶意主叫标识符(Caller ID)的呼叫,实现命令执行。当启用 文件名模板时,攻击者可在主叫方名称或号码中嵌入 shell 元字符(例如 )。一旦特权用户下载多个录音文件并打包为 ZIP 格式,这些命令将以 Web 服务器用户的身份被执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet