CVE-2009-1801
Summary
| CVE | CVE-2009-1801 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-05-28 14:30:00 UTC |
| Updated | 2019-12-10 15:34:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote attackers to inject arbitrary web script or HTML via the (1) display parameter to reports.php, the (2) order and (3) extdisplay parameters to config.php, and the (4) sort parameter to recordings/index.php. NOTE: some of these details are obtained from third party information. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Freepbx | Freepbx | 2.4 | All | All | All |
| Application | Freepbx | Freepbx | 2.4.0_beta1 | All | All | All |
| Application | Freepbx | Freepbx | 2.4.0_beta2 | All | All | All |
| Application | Freepbx | Freepbx | 2.4.1 | All | All | All |
| Application | Freepbx | Freepbx | 2.5.0rc2 | All | All | All |
| Application | Freepbx | Freepbx | 2.5.0rc3 | All | All | All |
| Application | Freepbx | Freepbx | 2.5.0_beta1 | All | All | All |
| Application | Freepbx | Freepbx | 2.5.1 | All | All | All |
| Application | Freepbx | Freepbx | 2.5.2 | All | All | All |
| Application | Freepbx | Freepbx | 2.4 | All | All | All |
| Application | Freepbx | Freepbx | 2.4.0_beta1 | All | All | All |
| Application | Freepbx | Freepbx | 2.4.0_beta2 | All | All | All |
| Application | Freepbx | Freepbx | 2.4.1 | All | All | All |
| Application | Freepbx | Freepbx | 2.5.0rc2 | All | All | All |
| Application | Freepbx | Freepbx | 2.5.0rc3 | All | All | All |
| Application | Freepbx | Freepbx | 2.5.0_beta1 | All | All | All |
| Application | Freepbx | Freepbx | 2.5.1 | All | All | All |
| Application | Freepbx | Freepbx | 2.5.2 | All | All | All |
| Application | Sangoma | Freepbx | 2.4.0 | All | All | All |
| Application | Sangoma | Freepbx | 2.5.0 | All | All | All |
| Application | Sangoma | Freepbx | 2.4.0 | All | All | All |
| Application | Sangoma | Freepbx | 2.5.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 54260 | OSVDB | osvdb.org | |
| freePBX Multiple Vulnerabilities - Advisories - Community | SECUNIA | secunia.com | Vendor Advisory |
| 54259 | OSVDB | osvdb.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| 54261 | OSVDB | osvdb.org | |
| #3660 (CSS and CSRF Security Vulnerabilities and User Account Enumeration) - FreePBX - Trac | CONFIRM | freepbx.org | |
| FreePBX Multiple Cross Site Scripting and Information Disclosure Vulnerabilities | BID | www.securityfocus.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.