S4E just found a medium log file scanner
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2017-14535 Scanner

Detects 'Command Injection' vulnerability in trixbox affects v. 2.8.0.4.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-14535
8.8
CVSS

trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Trixbox is an open-source telephony application platform that allows users to manage and control their phone systems. This powerful tool offers features such as voice over IP, call routing, and messaging, making it an essential asset for businesses worldwide. However, while Trixbox is widely recognized for its functionality, it happens to be vulnerable to several security issues, one of them being the CVE-2017-14535.

CVE-2017-14535 is a serious vulnerability that can grant attackers with unauthorized access to the Trixbox system. This vulnerability occurs due to an OS command injection flaw via shell metacharacters in the lang parameter to /maint/modules/home/index.php.

When this vulnerability is exploited, attackers can execute any code they desire, allowing them to inject malware, alter files, or even take full control over the Trixbox system. As a result, the attacker can gain access to sensitive business data stored in the system and use it for malicious purposes, potentially creating a significant threat to the organization.

At S4E, we understand the importance of keeping your digital assets secure. Our platform provides you with cutting-edge technology to identify vulnerabilities and threats, enabling you to keep your systems safe and protected. With S4E, you can get ahead of the curve and stay one step ahead of your adversaries. So, start your journey with us today, and safeguard your digital assets with ease.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users must take some precautions. These include:

  • Regularly installing software updates and patches
  • Disabling unused services and ports
  • Using strong passwords and enforcing password policies
  • Installing and enabling firewalls
  • Providing limited access rights to the system

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-14535 scanner - Command Injection vulnerability in trixbox S4E