Fujian Kelixun Command and Dispatch Management Platform OS Command Injection Vulnerability

Vulnerability

A critical command injection vulnerability has been identified in Fujian Kelixun version 1.0, specifically within the '/app/fax/fax_view.php' file. The vulnerability arises from inadequate validation of the 'fax_file' parameter, allowing attackers to inject malicious system commands that are executed without proper sanitization. This exploitation enables unauthorized control over the target server, potentially leading to a complete compromise of the system.

Impact

Exploitation of this vulnerability allows attackers to execute arbitrary commands on the server, gaining unauthorized access to the operating system. This could result in unauthorized control over the system, leakage or manipulation of sensitive data, disruption of services, and a serious overall threat to system security and business operations.

Reproduction

The vulnerability can be reproduced by sending a POST request to '/app/fax/fax_view.php' with a crafted 'fax_file' parameter that includes injected commands. The injected commands are executed on the server, demonstrating the command injection flaw.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.