PT-2007-3683 · Sangoma · Freepbx

Xenomuta

·

Publicado

2007-04-30

·

Atualizado

2011-03-08

·

CVE-2007-2350

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions freePBX versions 2.2.x
Description The issue allows remote authenticated administrators to execute arbitrary commands. This is achieved by injecting shell metacharacters in the del parameter of the admin/config.php file in the music-on-hold module.
Recommendations For freePBX versions 2.2.x, consider restricting access to the music-on-hold module until a patch is available. As a temporary workaround, avoid using the del parameter in the admin/config.php file to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2350

Produtos afetados

Freepbx