6.5
CVSSv2

CVE-2014-9001

Published: 20/11/2014 Updated: 20/11/2014
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) APPTMIN, (2) APPTHR, (3) APPTDA, (4) APPTMO, (5) APPTYR, or (6) APPTPHONE parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

incrediblepbx incredible pbx 11 2.0.6.5.0

Exploits

#!/usr/bin/perl # # Title: Incredible PBX remote command execution exploit # Author: Simo Ben youssef # Contact: Simo_at_Morxploit_com # Discovered: 1 September 2014 # Coded: 21 October 2014 # Published: 21 October 2014 # MorXploit Research # wwwMorXploitcom # Vendor: PBX in a Flash # Vendor url: pbxinaflashnet/ # Software: Incredi ...