{
    "id": "CVE-2014-9001",
    "published": "2014-11-20 13:55:11",
    "last_modified": "2026-06-17 00:17:38",
    "cvss_score": "6.5",
    "cvss_severity": "MEDIUM",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
    "cwe": "CWE-94",
    "description": "reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) APPTMIN, (2) APPTHR, (3) APPTDA, (4) APPTMO, (5) APPTYR, or (6) APPTPHONE parameters.",
    "epss_score": "0.02800",
    "epss_percentile": "0.86017",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-06 18:17:12",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "incrediblepbx",
            "product": "incredible_pbx_11"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "35080",
            "title": "Incredible PBX 2.0.6.5.0 - Remote Command Execution",
            "date": "2014-10-27",
            "url": "https://www.exploit-db.com/exploits/35080"
        }
    ],
    "refs_list": [
        "http://seclists.org/fulldisclosure/2014/Oct/101",
        "http://seclists.org/fulldisclosure/2014/Oct/101"
    ]
}