CVE-2014-1903
Summary
| CVE | CVE-2014-1903 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-02-18 11:55:00 UTC |
| Updated | 2019-12-10 16:01:00 UTC |
| Description | admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execute arbitrary PHP code via the function and args parameters to admin/config.php. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Freepbx | Freepbx | 2.10 | All | All | All |
| Application | Freepbx | Freepbx | 2.11 | All | All | All |
| Application | Freepbx | Freepbx | 2.12 | All | All | All |
| Application | Freepbx | Freepbx | 2.10 | All | All | All |
| Application | Freepbx | Freepbx | 2.11 | All | All | All |
| Application | Freepbx | Freepbx | 2.12 | All | All | All |
| Application | Sangoma | Freepbx | 2.9 | All | All | All |
| Application | Sangoma | Freepbx | 2.9 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 20140211 Re: Freepbx , php code execution exploit | FULLDISC | archives.neohapsis.com | |
| FreePBX 2.9 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| code.freepbx.org/changelog/FreePBX_SVN | CONFIRM | code.freepbx.org | |
| FreePBX 2.x Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| [FREEPBX-7123] Exec shell on a host using bug in config.php - FreePBX Issue Tracker | CONFIRM | issues.freepbx.org | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| code.freepbx.org/changelog/FreePBX_Framework | CONFIRM | code.freepbx.org | |
| Log in - Sangoma Issue Tracker | CONFIRM | issues.freepbx.org | Vendor Advisory |
| oldays/CVE-2014-1903.pl at master · 0x00string/oldays · GitHub | MISC | github.com | |
| 20140211 Freepbx , php code execution exploit | FULLDISC | archives.neohapsis.com | |
| Security Vulnerability Notice | FreePBX | CONFIRM | www.freepbx.org | |
| 103240 | OSVDB | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.