← Vulnerability feed

Vulnerability record · CVE-2010-0702 · published 23 February 2010

CVE-2010-0702: Netfortris trixbox sql injection vulnerability

Netfortris · Trixbox

SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

7.5 CVSS 2.0 High EPSS 4.1% · top 9.6% CWE-89 · SQL injection
7.5CVSS 2.0 base score
4.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-0702 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-7351Trixbox CE endpoint_devicemap.php OS command injectionFonality Trixbox Community Edition contains an OS command injection flaw in endpoint_devicemap.php. An attacker with low-privileged access can run ar…EPSS 65%analysed8.8CVE-2017-14535trixbox lang parameter OS command injectiontrixbox 2.8.0.4 passes the lang parameter to /maint/modules/home/index.php without sanitizing shell metacharacters, allowing OS command injection. An…EPSS 50%analysed7.5CVE-2014-5109Netfortris trixbox sql injection vulnerabilitySQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL co…EPSS 3.4%7.5CVE-2014-5112Netfortris trixbox code injection vulnerabilitymaint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter.EPSS 9.2%6.5CVE-2017-14537Netfortris trixbox path traversal vulnerabilitytrixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.…EPSS 39%5.4CVE-2017-14536Netfortris trixbox cross-site scripting vulnerabilitytrixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.EPSS 0.60%5.0CVE-2014-5111Netfortris trixbox path traversal vulnerabilityMultiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parame…EPSS 22%4.3CVE-2014-5110Netfortris trixbox cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in user/help/html/index.php in Fonality trixbox allows remote attackers to inject arbitrary web script or HT…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2010-0702), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.