← Vulnerability feed

Vulnerability record · CVE-2013-4467 · published 11 March 2014

CVE-2013-4467: Vicidial sql injection vulnerability

Vicidial · Vicidial

Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to execute arbitrary SQL commands via the campaign variable in SCRIPT_multirecording_AJAX.php, (2) remote authenticated users to execute arbitrary SQL commands via the server_ip parameter to manager_send.php, or (3) other unspecified vectors. NOTE: some of these details are obtained from third party information.

6.5 CVSS 2.0 Medium EPSS 32% · top 1.8% CWE-89 · SQL injection
6.5CVSS 2.0 base score
32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 10 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to execute arbitrary SQL commands via the campaign variable in SCRIPT_multirecording_AJAX.php, (2) remote authenticated users to execute arbitrary SQL commands via the server_ip parameter to manager_send.php, or (3) other unspecified vectors. NOTE: some of these details are obtained from third party information.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-4467 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-34876Vicidial sql injection vulnerabilitySQL Injection vulnerability in admin interface (/vicidial/admin.php) of VICIdial via modify_email_accounts, access_recordings, and agentcall_email pa…EPSS 3.4%8.8CVE-2022-34877Vicidial sql injection vulnerabilitySQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the agent parameter allows attack…EPSS 3.3%8.8CVE-2022-34878Vicidial sql injection vulnerabilitySQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download parameter allows attacker to spoof i…EPSS 3.3%6.5CVE-2013-4468Vicidial vulnerabilityVICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shel…EPSS 32%6.1CVE-2021-35377Vicidial cross-site scripting vulnerabilityCross Site Scripting vulnerability found in VICIdial v2.14-610c and v.2.10-415c allows attackers execute arbitrary code via the /agc/vicidial.php, ag…EPSS 0.40%6.1CVE-2022-34879Vicidial cross-site scripting vulnerabilityReflected Cross Site Scripting (XSS) vulnerabilities in AST Agent Time Sheet interface (/vicidial/AST_agent_time_sheet.php) of VICIdial via agent, an…EPSS 0.52%5.4CVE-2021-46557Vicidial cross-site scripting vulnerabilityVicidial 2.14-783a was discovered to contain a cross-site scripting (XSS) vulnerability via the input tabs.EPSS 0.56%5.0CVE-2013-7382Vicidial vulnerabilityVICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for the (1) VDAD and (2) VDCL user…EPSS 2.8%

Source: NIST National Vulnerability Database (record CVE-2013-4467), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.