vendor:
Trixbox
by:
Ron Jost (Hacker5preme)
8.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Trixbox
Affected Version From: 2.8.0.4
Affected Version To: 2.8.0.4
Patch Exists: YES
Related CWE: CVE-2017-14535
CPE: a:trixbox:trixbox:2.8.0.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Xubuntu 20.04
2021
Trixbox 2.8.0.4 – ‘lang’ Remote Code Execution (Unauthenticated)
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php
Mitigation:
Update to the latest version of Trixbox