vendor:
PBX Business Phone Application
by:
Global-Evolution Security Team
1.11.2002
CVSS
LOW
Multiple Cross Site Scripting (Server-Side & Client-Side)
79,8
CWE
Product Name: PBX Business Phone Application
Affected Version From: v2.6.x
Affected Version To: 2.5.2.x
Patch Exists: NO
Related CWE: Unknown
CPE: a:freepbx:freepbx
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 VBox
2009
PenTest Information
Multiple XSS Vulnerabilities are detected on client-side(persistent). An attacker with low privilegs is able to include own bad script routines on client-side(Example;PHP;JS) of the phone application. Attackers can get Session-Data(Cookies) of customers/admins over multiple XSS vulnerabilities. Multiple XSS Vulnerabilities are detected on server-side(persistent). An attacker with low privilegs is able to include own bad script routines on server-side(Example;PHP;JS) of the phone application. Attackers can get Session-Data(Cookies) of customers/admins over multiple XSS vulnerabilities.
Mitigation:
Apply the latest security patches and updates to the system.