peter bassill · operator
$ cve CVE-2005-3539 JSON

CVE-2005-3539 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 12.7% (pctl 96)

Patch early

A public exploit exists.

Description

Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS12.65% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2005-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
hylafaxhylafax

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD