FreePBX 'index.php' Remote Command Execution Vulnerability
BID:70188
Info
FreePBX 'index.php' Remote Command Execution Vulnerability
| Bugtraq ID: | 70188 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7235 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2014 12:00AM |
| Updated: | Oct 06 2014 12:02AM |
| Credit: | James Finstrom |
| Vulnerable: |
freePBX freePBX 2.10 freePBX freePBX 2.9 freePBX freePBX 2.5.2 freePBX freePBX 2.5.1 freePBX freePBX 2.4.1 freePBX freePBX 2.2.1 freePBX freePBX 2.1.3 freePBX freePBX 2.8.0 freePBX freePBX 2.6 freePBX freePBX 2.5 freePBX freePBX 2.4 |
| Not Vulnerable: | |
Discussion
FreePBX 'index.php' Remote Command Execution Vulnerability
FreePBX is prone to a remote command-execution vulnerability because the application fails to sufficiently sanitize input data.
An attacker may leverage this issue to execute arbitrary commands in the context of the affected application.
FreePBX is prone to a remote command-execution vulnerability because the application fails to sufficiently sanitize input data.
An attacker may leverage this issue to execute arbitrary commands in the context of the affected application.
Exploit / POC
FreePBX 'index.php' Remote Command Execution Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
FreePBX 'index.php' Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
FreePBX 'index.php' Remote Command Execution Vulnerability
References:
References:
- freePBX Homepage (Coalescent Systems Inc.)