Release date: 2010-09-23
Updated on: 2010-09-26
Affected Systems:
FreePBX 2.8.0
Description:
--------------------------------------------------------------------------------
Previously called Asterisk Management Portal, FreePBX is a standardized implementation of the IP telephone tool Asterisk and provides Web configuration interfaces and other tools.
FreePBX does not properly filter src, dst, and channel parameters submitted to admin/config. php when searching for call details reports. Remote attackers can execute SQL injection attacks by submitting malicious query requests.
<* Source: Marsh Ray
Link: http://secunia.com/advisories/41558/
Http://marc.info /? L = full-disclosure & m = 128509767426735 & w = 2
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
FreePBX
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://freepbx.org/trac