Vulnerability CVE-2014-1903


Published: 2014-02-18

Description:
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execute arbitrary PHP code via the function and args parameters to admin/config.php.

See advisories in our WLB2 database:
Topic
Author
Date
High
FreePBX config.php Remote Code Execution
xistence
25.03.2014

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Freepbx -> Freepbx 

 References:
http://archives.neohapsis.com/archives/fulldisclosure/2014-02/0097.html
http://archives.neohapsis.com/archives/fulldisclosure/2014-02/0111.html
http://code.freepbx.org/changelog/FreePBX_Framework?cs=a29382efeb293ef4f42aa9b841dfc8eabb2d1e03
http://code.freepbx.org/changelog/FreePBX_SVN?cs=16429
http://issues.freepbx.org/browse/FREEPBX-7117
http://issues.freepbx.org/browse/FREEPBX-7123
http://packetstormsecurity.com/files/125166/FreePBX-2.x-Code-Execution.html
http://packetstormsecurity.com/files/125215/FreePBX-2.9-Remote-Code-Execution.html
http://www.freepbx.org/news/2014-02-06/security-vulnerability-notice
http://www.securityfocus.com/archive/1/531040/100/0/threaded
https://github.com/0x00string/oldays/blob/master/CVE-2014-1903.pl

Copyright 2024, cxsecurity.com

 

Back to Top