Input validation error in Asterisk Open Source - CVE-2014-4046
Published: June 17, 2014 / Updated: August 4, 2020
Asterisk Open Source
Detailed vulnerability description
The vulnerability allows a remote #AU# to read and manipulate data.
Asterisk Open Source 11.x before 11.10.1 and 12.x before 12.3.1 and Certified Asterisk 11.6 before 11.6-cert3 allows remote authenticated Manager users to execute arbitrary shell commands via a MixMonitor action. Per: http://cwe.mitre.org/data/definitions/77.html "CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')"