Security Advisory

CVE-2014-5111

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-07-28 15:00:00
Last updated 2024-09-16 19:51:36
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to (1) home/index.php, (2) asterisk_info/asterisk_info.php, (3) repo/repo.php, or (4) endpointcfg/endpointcfg.php in maint/modules/.