FreePBX System Recordings Menu Arbitrary File Upload Vulnerability
BID:43454
Info
FreePBX System Recordings Menu Arbitrary File Upload Vulnerability
| Bugtraq ID: | 43454 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-3490 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2010 12:00AM |
| Updated: | Sep 24 2010 03:11PM |
| Credit: | Wendel G. Henrique of Trustwave's SpiderLabs |
| Vulnerable: |
freePBX freePBX 2.5.2 freePBX freePBX 2.5.1 freePBX freePBX 2.4.1 freePBX freePBX 2.2.1 freePBX freePBX 2.2 rc1 freePBX freePBX 2.1.3 freePBX freePBX trunk freePBX freePBX 2.8.0 freePBX freePBX 2.6 freePBX freePBX 2.5 freePBX freePBX 2.4 |
| Not Vulnerable: | |
Discussion
FreePBX System Recordings Menu Arbitrary File Upload Vulnerability
FreePBX is prone to an arbitrary file-upload vulnerability because it fails to properly sanitize user-supplied input.
An attacker can leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the webserver.
FreePBX 2.8.0 is vulnerable; other versions may also be affected.
FreePBX is prone to an arbitrary file-upload vulnerability because it fails to properly sanitize user-supplied input.
An attacker can leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the webserver.
FreePBX 2.8.0 is vulnerable; other versions may also be affected.
Exploit / POC
FreePBX System Recordings Menu Arbitrary File Upload Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
FreePBX System Recordings Menu Arbitrary File Upload Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.