PT-2007-7276 · Fonality · Fonality Trixbox

Published

2007-12-18

·

Updated

2024-02-14

·

CVE-2007-6424

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Fonality Trixbox version 2.0
Description The issue allows remote attackers to execute arbitrary commands via a DNS spoofing attack, as the registry.pl script reads and executes commands from a remote web site without proper validation. This can lead to the disabling of trixbox.
Recommendations For Fonality Trixbox version 2.0, consider restricting access to the registry.pl script until a proper fix is available, and ensure that the environment in which it is running is secure to minimize the risk of DNS spoofing attacks.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2007-6424

Affected Products

Fonality Trixbox