FreePBX Shell Command Execution Vulnerability
BID:19212
Info
FreePBX Shell Command Execution Vulnerability
| Bugtraq ID: | 19212 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 28 2006 12:00AM |
| Updated: | Jul 28 2006 11:17PM |
| Credit: | Clement Cerdini reported this issue. |
| Vulnerable: |
OSSP Sheila 1.1.5 OSSP Sheila 1.1.4 |
| Not Vulnerable: |
OSSP Sheila 1.1.7 |
Discussion
FreePBX Shell Command Execution Vulnerability
FreePBX is prone to a vulnerability that may permit the execution of arbitrary shell commands.
An attacker may employ shell escape characters to execute malicious shell code with the privileges of users executing a vulnerable version of the application.
This issue reportedly affects versions 2.1.1. and prior.
NOTE: To be vulnerable, this application must be configured with the 'Allow anonymous inbound SIP calls' option.
FreePBX is prone to a vulnerability that may permit the execution of arbitrary shell commands.
An attacker may employ shell escape characters to execute malicious shell code with the privileges of users executing a vulnerable version of the application.
This issue reportedly affects versions 2.1.1. and prior.
NOTE: To be vulnerable, this application must be configured with the 'Allow anonymous inbound SIP calls' option.
Exploit / POC
FreePBX Shell Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
FreePBX Shell Command Execution Vulnerability
Solution:
The vendor has released a CVS fix to address this issue; please see the reference section for more information.
Solution:
The vendor has released a CVS fix to address this issue; please see the reference section for more information.
References
FreePBX Shell Command Execution Vulnerability
References:
References:
- FreePBX 2.1.1 CVS fix is available (FreePBX)
- FreePBX Homepage (FreePBX)