Trixbox 2.8.0.4 is susceptible to path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
View the template here CVE-2017-14537.yaml
References:
https://sourceforge.net/projects/asteriskathome/