vendor:
Trixbox
by:
Ron Jost (Hacker5preme)
6.5
CVSS
MEDIUM
Path Traversal
22
CWE
Product Name: Trixbox
Affected Version From: 2.8.0.4
Affected Version To: 2.8.0.4
Patch Exists: YES
Related CWE: CVE-2017-14537
CPE: a:trixbox:trixbox:2.8.0.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Xubuntu 20.04
2021
Trixbox 2.8.0.4 – ‘lang’ Path Traversal
Trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
Mitigation:
Ensure that user-supplied input is validated and sanitized before being used in a file path.