Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
freepbx freepbx 2.5.1 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2009-1801
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote malicious users to inject arbitrary web script or HTML via the (1) display parameter to reports.php, the (2) order and (3) extdisplay paramet...
Sangoma Freepbx 2.5.0
Freepbx Freepbx 2.4.0 Beta2
Freepbx Freepbx 2.5.1
Freepbx Freepbx 2.5.2
Freepbx Freepbx 2.5.0rc3
Freepbx Freepbx 2.4.1
Sangoma Freepbx 2.4.0
Freepbx Freepbx 2.5.0rc2
Freepbx Freepbx 2.5.0 Beta1
Freepbx Freepbx 2.4.0 Beta1
Freepbx Freepbx 2.4
6.8
CVSSv2
CVE-2009-1802
Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote malicious users to hijack the authentication of admins for requests that create a new admin account or have unspecified other impact.
Freepbx Freepbx 2.4.1
Freepbx Freepbx 2.4.0 Beta2
Freepbx Freepbx 2.4.0 Beta1
Sangoma Freepbx 2.4.0
Freepbx Freepbx 2.5.2
Freepbx Freepbx 2.5.1
Freepbx Freepbx 2.5.0rc3
Freepbx Freepbx 2.5.0rc2
Sangoma Freepbx 2.5.0
Freepbx Freepbx 2.5.0 Beta1
Freepbx Freepbx 2.5
Freepbx Freepbx 2.4
5
CVSSv2
CVE-2009-1803
FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt depending on whether the user account exists, which allows remote malicious users to enumerate valid usernames.
Freepbx Freepbx 2.5.0rc2
Freepbx Freepbx 2.5.0 Beta1
Sangoma Freepbx 2.5.0
Freepbx Freepbx 2.5
Freepbx Freepbx 2.4.1
Freepbx Freepbx 2.5.2
Freepbx Freepbx 2.5.0rc3
Freepbx Freepbx 2.4.0 Beta1
Freepbx Freepbx 2.4
Freepbx Freepbx 2.5.1
Freepbx Freepbx 2.4.0 Beta2
Sangoma Freepbx 2.4.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started