Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sangoma vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2019-12148
The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerability involving special characters in the username field. Upon successful exploitation, a remote unauthenticated user can login into...
Sangoma Session Border Controller Firmware 2.3.23-119-ga
668
VMScore
CVE-2017-17430
Sangoma NetBorder / Vega Session Controller prior to 2.3.12-80-GA allows remote malicious users to execute arbitrary commands via the web interface.
Sangoma Netborder\\/vega Session Firmware 2.3.11-78-ga
383
VMScore
CVE-2019-16967
An issue exists in Manager 13.x prior to 13.0.2.6 and 15.x prior to 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized managerdisplay variable coming from the URL is reflected in HTML, leading to XSS. It can be ...
Freepbx Manager
Sangoma Freepbx
Freepbx Manager 13.0.1
383
VMScore
CVE-2019-16966
An issue exists in Contactmanager 13.x prior to 13.0.45.3, 14.x prior to 14.0.5.12, and 15.x prior to 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\modules\contactmanager\Contactmanager.class.php), an unsanitized group variable coming from the URL is re...
Freepbx Contactmanager 13.0.0
Freepbx Contactmanager 14.0.1
Freepbx Contactmanager
Sangoma Freepbx 14.0.10.3
383
VMScore
CVE-2009-1801
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote malicious users to inject arbitrary web script or HTML via the (1) display parameter to reports.php, the (2) order and (3) extdisplay paramet...
Sangoma Freepbx 2.5.0
Freepbx Freepbx 2.4.0 Beta2
Freepbx Freepbx 2.5.1
Freepbx Freepbx 2.5.2
Freepbx Freepbx 2.5.0rc3
Freepbx Freepbx 2.4.1
Sangoma Freepbx 2.4.0
Freepbx Freepbx 2.5.0rc2
Freepbx Freepbx 2.5.0 Beta1
Freepbx Freepbx 2.4.0 Beta1
Freepbx Freepbx 2.4
760
VMScore
CVE-2014-1903
admin/libraries/view.functions.php in FreePBX 2.9 prior to 2.9.0.14, 2.10 prior to 2.10.1.15, 2.11 prior to 2.11.0.23, and 12 prior to 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote malicious users to execute arbitrary PHP ...
Freepbx Freepbx 2.11
Freepbx Freepbx 2.10
Sangoma Freepbx 2.9
Freepbx Freepbx 2.12
2 EDB exploits
605
VMScore
CVE-2009-1802
Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote malicious users to hijack the authentication of admins for requests that create a new admin account or have unspecified other impact.
Freepbx Freepbx 2.4.1
Freepbx Freepbx 2.4.0 Beta2
Freepbx Freepbx 2.4.0 Beta1
Sangoma Freepbx 2.4.0
Freepbx Freepbx 2.5.2
Freepbx Freepbx 2.5.1
Freepbx Freepbx 2.5.0rc3
Freepbx Freepbx 2.5.0rc2
Sangoma Freepbx 2.5.0
Freepbx Freepbx 2.5.0 Beta1
Freepbx Freepbx 2.5
Freepbx Freepbx 2.4
445
VMScore
CVE-2009-1803
FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt depending on whether the user account exists, which allows remote malicious users to enumerate valid usernames.
Freepbx Freepbx 2.5.0rc2
Freepbx Freepbx 2.5.0 Beta1
Sangoma Freepbx 2.5.0
Freepbx Freepbx 2.5
Freepbx Freepbx 2.4.1
Freepbx Freepbx 2.5.2
Freepbx Freepbx 2.5.0rc3
Freepbx Freepbx 2.4.0 Beta1
Freepbx Freepbx 2.4
Freepbx Freepbx 2.5.1
Freepbx Freepbx 2.4.0 Beta2
Sangoma Freepbx 2.4.0
571
VMScore
CVE-2022-21723
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potential...
Teluu Pjsip
Asterisk Certified Asterisk 16.8.0
Sangoma Asterisk
Debian Debian Linux 9.0
Debian Debian Linux 10.0
668
VMScore
CVE-2022-23608
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario, a hash key shared by multipl...
Teluu Pjsip
Asterisk Certified Asterisk 16.8.0
Asterisk Certified Asterisk
Sangoma Asterisk
Debian Debian Linux 9.0
Debian Debian Linux 10.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-17519
open redirect
CVE-2024-21683
cache poisoning
CVE-2021-47524
CVE-2021-47521
CVE-2024-5229
CVE-2021-47560
local
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »