← Vulnerability feed

Vulnerability record · CVE-2007-6424 · published 18 December 2007

CVE-2007-6424: Netfortris trixbox permissions and access controls vulnerability

Netfortris · Trixbox

registry.pl in Fonality Trixbox 2.0 PBX products, when running in certain environments, reads and executes a set of commands from a remote web site without sufficiently validating the origin of the commands, which allows remote attackers to disable trixbox and execute arbitrary commands via a DNS spoofing attack.

4.3 CVSS 2.0 Medium EPSS 2.5% · top 16.0% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

registry.pl in Fonality Trixbox 2.0 PBX products, when running in certain environments, reads and executes a set of commands from a remote web site without sufficiently validating the origin of the commands, which allows remote attackers to disable trixbox and execute arbitrary commands via a DNS spoofing attack.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-6424 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-7351Trixbox CE endpoint_devicemap.php OS command injectionFonality Trixbox Community Edition contains an OS command injection flaw in endpoint_devicemap.php. An attacker with low-privileged access can run ar…EPSS 65%analysed8.8CVE-2017-14535trixbox lang parameter OS command injectiontrixbox 2.8.0.4 passes the lang parameter to /maint/modules/home/index.php without sanitizing shell metacharacters, allowing OS command injection. An…EPSS 50%analysed7.5CVE-2014-5109Netfortris trixbox sql injection vulnerabilitySQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL co…EPSS 3.4%7.5CVE-2014-5112Netfortris trixbox code injection vulnerabilitymaint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter.EPSS 9.2%7.5CVE-2010-0702Netfortris trixbox sql injection vulnerabilitySQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands…EPSS 4.2%6.5CVE-2017-14537Netfortris trixbox path traversal vulnerabilitytrixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.…EPSS 39%5.4CVE-2017-14536Netfortris trixbox cross-site scripting vulnerabilitytrixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.EPSS 0.60%5.0CVE-2014-5111Netfortris trixbox path traversal vulnerabilityMultiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parame…EPSS 22%

Source: NIST National Vulnerability Database (record CVE-2007-6424), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.