Trixbox 2.8.0.4 Remote Code Execution

Trixbox version 2.8.0.4 has an OS command injection vulnerability that can be leveraged via shell metacharacters in the lang parameter to /maint/modules/home/index.php.

Leave a Reply