FreePBX 'page.backup.php' Script Remote Command Execution Vulnerability
BID:59533
Info
FreePBX 'page.backup.php' Script Remote Command Execution Vulnerability
| Bugtraq ID: | 59533 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2013 12:00AM |
| Updated: | Apr 27 2013 12:00AM |
| Credit: | Ahmed Aboul-Ela |
| Vulnerable: |
freePBX freePBX 2.5.2 freePBX freePBX 2.5.1 freePBX freePBX 2.4.1 freePBX freePBX 2.9 freePBX freePBX 2.8.0 freePBX freePBX 2.6 freePBX freePBX 2.5 freePBX freePBX 2.4 |
| Not Vulnerable: |
freePBX freePBX 2.10 |
Discussion
FreePBX 'page.backup.php' Script Remote Command Execution Vulnerability
FreePBX is prone to a remote command-execution vulnerability because the application fails to sufficiently sanitize input data.
An attacker may leverage this issue to execute arbitrary commands in the context of the affected application.
FreePBX 2.9 is vulnerable; other versions may also be affected.
FreePBX is prone to a remote command-execution vulnerability because the application fails to sufficiently sanitize input data.
An attacker may leverage this issue to execute arbitrary commands in the context of the affected application.
FreePBX 2.9 is vulnerable; other versions may also be affected.
Exploit / POC
FreePBX 'page.backup.php' Script Remote Command Execution Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
FreePBX 'page.backup.php' Script Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
FreePBX 'page.backup.php' Script Remote Command Execution Vulnerability
References:
References:
- freePBX Homepage (Coalescent Systems Inc.)
- mbrevda: fix remote command execution vulnerability (FreePBX)