FreePBX cross-site scripting and Command Injection Vulnerability
Release date:
Updated on:
Affected Systems:
FreePBX 2.9
FreePBX 2.10
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52630
Cve id: CVE-2012-4869
Previously called Asterisk Management Portal, FreePBX is a standardized implementation of the IP telephone tool Asterisk and provides Web configuration interfaces and other tools.
The callme_startcall function in FreePBX 2.9, 2.10, and earlier versions allows remote attackers to execute arbitrary commands through the callmenum parameter in c operations.
<* Source: Martin Tschirsich
Link: http://secunia.com/advisories/48463
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
FreePBX
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://freepbx.org/trac