FreePBX 'admin/cdr/call-comp.php' Multiple SQL Injection Vulnerabilities
BID:43375
Info
FreePBX 'admin/cdr/call-comp.php' Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 43375 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2010 12:00AM |
| Updated: | Oct 01 2010 06:00PM |
| Credit: | Marsh Ray |
| Vulnerable: |
freePBX freePBX trunk |
| Not Vulnerable: | |
Discussion
FreePBX 'admin/cdr/call-comp.php' Multiple SQL Injection Vulnerabilities
FreePBX is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
FreePBX is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
FreePBX 'admin/cdr/call-comp.php' Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
FreePBX 'admin/cdr/call-comp.php' Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
FreePBX 'admin/cdr/call-comp.php' Multiple SQL Injection Vulnerabilities
References:
References:
- Freepbx (Marsh Ray
) - FreePBX Homepage (FreePBX)
- Revision 10274 (mbrevda)
- Ticket #4526 Move cdr specific files to cdr/ (mbrevda)