← All CVEs

CVE-2005-3539

high · 7.5

Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.

7.5
CVSS
12.7%
EPSS (exploit prob.)
96th
EPSS percentile
2005-12-31
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
hylafaxhylafax4.1.1
hylafaxhylafax4.2
hylafaxhylafax4.2.1
hylafaxhylafax4.2.2
hylafaxhylafax4.2.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2005-3539