← Vulnerability feed

Vulnerability record · CVE-2014-5111 · published 28 July 2014

CVE-2014-5111: Netfortris trixbox path traversal vulnerability

Netfortris · Trixbox

Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to (1) home/index.php, (2) asterisk_info/asterisk_info.php, (3) repo/repo.php, or (4) endpointcfg/endpointcfg.php in maint/modules/.

5.0 CVSS 2.0 Medium EPSS 22% · top 2.5% CWE-22 · Path traversal
5.0CVSS 2.0 base score
22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to (1) home/index.php, (2) asterisk_info/asterisk_info.php, (3) repo/repo.php, or (4) endpointcfg/endpointcfg.php in maint/modules/.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-5111 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-7351Trixbox CE endpoint_devicemap.php OS command injectionFonality Trixbox Community Edition contains an OS command injection flaw in endpoint_devicemap.php. An attacker with low-privileged access can run ar…EPSS 65%analysed8.8CVE-2017-14535trixbox lang parameter OS command injectiontrixbox 2.8.0.4 passes the lang parameter to /maint/modules/home/index.php without sanitizing shell metacharacters, allowing OS command injection. An…EPSS 50%analysed7.5CVE-2014-5109Netfortris trixbox sql injection vulnerabilitySQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL co…EPSS 3.4%7.5CVE-2014-5112Netfortris trixbox code injection vulnerabilitymaint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter.EPSS 9.2%7.5CVE-2010-0702Netfortris trixbox sql injection vulnerabilitySQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands…EPSS 4.1%6.5CVE-2017-14537Netfortris trixbox path traversal vulnerabilitytrixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.…EPSS 39%5.4CVE-2017-14536Netfortris trixbox cross-site scripting vulnerabilitytrixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.EPSS 0.60%4.3CVE-2014-5110Netfortris trixbox cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in user/help/html/index.php in Fonality trixbox allows remote attackers to inject arbitrary web script or HT…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2014-5111), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.