vendor:
FreePBX
by:
Ivan Huertas
6,3
CVSS
MEDIUM
SQL injection
89
CWE
Product Name: FreePBX
Affected Version From: 2.5.1
Affected Version To: 2.5.1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Any running FreePBX 2.5.1
2010
SQL injection in FreePBX 2.5.1
A vulnerability has been discovered in FreePBX, which can be exploited by malicious people to conduct SQL injection attacks. Input passed via the "extdisplay" parameter to config.php is not properly sanitized before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Mitigation:
Update to FreePBX 2.5.2 or greater