This Metasploit module exploits an authenticated command injection vulnerability in FusionPBX versions 4.4.3 and prior. The exec.php file within the Operator Panel permits users with operator_panel_view permissions, or administrator permissions, to execute arbitrary commands as the web server user by sending a system command to the FreeSWITCH event socket interface. This module has been tested successfully on FusionPBX version 4.4.1 on Ubuntu 19.04 (x64).
8371c066836fe4c5336f32a7b5aa18d5
FusionPBX versions 4.4.3 and below suffer from a remote code execution vulnerability via cross site scripting.
fceaec3a265cd08a10da41887c689047
BlogEngine.NET version 3.3.6 suffers from code execution and directory traversal vulnerabilities.
5d60a05646610a370fa6e7cddfe9d0f6