← All CVEs

CVE-2013-4468

medium · 6.5

VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in the extension parameter in an OriginateVDRelogin action to manager_send.php.

6.5
CVSS
32.3%
EPSS (exploit prob.)
98th
EPSS percentile
2014-05-14
Published

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

VendorProductAffected versions
vicidialvicidial<= 2.8
vicidialvicidial2.7
vicidialvicidial2.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-4468