vendor:
VoipNow Service Provider Edition
by:
Faris, aka i-Hmx
7,5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: VoipNow Service Provider Edition
Affected Version From: VoipNow Service Provider Edition prior to 2.3
Affected Version To: VoipNow Service Provider Edition prior to 2.3
Patch Exists: YES
Related CWE: N/A
CPE: 4psa:voipnow_service_provider_edition
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
4psa VoipNow < 2.3 , Remote Command Execution vuln
VoipNow Service Provider Edition is prone to a remote arbitrary command-execution vulnerability because it fails to properly validate user-supplied input. An attacker can exploit this issue to execute arbitrary commands within the context of the vulnerable application.
Mitigation:
Upgrade to VoipNow Service Provider Edition version 2.3 or later.