Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Inj3Ctor3

#23444de 53,635
10CVSS total
Vulnerabilidades · 1
PT-2014-7848
10
2014-10-07
Sangoma · Freepbx · CVE-2014-7235
**Name of the Vulnerable Software and Affected Versions** FreePBX versions prior to 2.9.0.9 FreePBX versions 2.10.x FreePBX versions prior to 2.11.1.5 **Description** The issue allows remote attackers to execute arbitrary code via the `ari auth` cookie, related to the PHP unserialize function. This has been exploited in the wild. **Recommendations** For versions prior to 2.9.0.9, update to version 2.9.0.9 or later. For versions 2.10.x, consider upgrading to a newer version series. For versions prior to 2.11.1.5, update to version 2.11.1.5 or later. As a temporary workaround, consider restricting access to the `htdocs ari/includes/login.php` file until a patch is available.