SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Xorcom CompletePBX task scheduler Command Injection

Category: WEB-ATTACKS      

A critical vulnerability in the task scheduler module of Xorcom CompletePBX 5.2.35 allows an authenticated user to execute arbitrary system commands as root. This stems from insufficient input sanitization in task parameters, leading to a direct command injection opportunity.


Relevant Information