Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bsd | Bsd | All versions |
| Hp | Hp-Ux | All versions |
| Hp | Tru64 | All versions |
| Ibm | Aix | All versions |
| Linux | Linux Kernel | All versions |
| Santa Cruz Operation | Sco Unix | All versions |
| Sun | Solaris | All versions |
| Freepbx | Freepbx | 2.2.1 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053882.htmlExploit
- http://osvdb.org/35315
- http://secunia.com/advisories/24935
- http://securityreason.com/securityalert/2627
- http://www.securityfocus.com/bid/23575
- http://www.vupen.com/english/advisories/2007/1535
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33772
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053882.htmlExploit
- http://osvdb.org/35315
- http://secunia.com/advisories/24935
- http://securityreason.com/securityalert/2627
- http://www.securityfocus.com/bid/23575
- http://www.vupen.com/english/advisories/2007/1535
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33772
FAQ
What is CVE-2007-2191?
CVE-2007-2191 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecifie...
How severe is CVE-2007-2191?
CVE-2007-2191 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2191?
Check the references section above for vendor advisories and patch information. Affected products include: Bsd Bsd, Hp Hp-Ux, Hp Tru64, Ibm Aix, Linux Linux Kernel.