vendor:
FreePBX
by:
inj3ctor3
9,3
CVSS
HIGH
Zero-Day Remote Code Execution and Privilege Escalation
20
CWE
Product Name: FreePBX
Affected Version From: FreePBX 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5
Affected Version To: FreePBX 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5
Patch Exists: Yes
Related CWE: CVE-2014-7235
CPE: a:freepbx:freepbx
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Centos 6
2016
Freepbx coockie recordings injection
A critical Zero-Day Remote Code Execution and Privilege Escalation exploit within the legacy “FreePBX ARI Framework module/Asterisk Recording Interface (ARI)”. htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth coockie, related to the PHP unserialize function.
Mitigation:
Update to the latest version of FreePBX.