Vulnerability Description
admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the del parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freepbx | Freepbx | <= 2.2.1 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053915.htmlExploit
- http://osvdb.org/35316
- http://secunia.com/advisories/24935Vendor Advisory
- http://securityreason.com/securityalert/2652
- http://www.vupen.com/english/advisories/2007/1535
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053915.htmlExploit
- http://osvdb.org/35316
- http://secunia.com/advisories/24935Vendor Advisory
- http://securityreason.com/securityalert/2652
- http://www.vupen.com/english/advisories/2007/1535
FAQ
What is CVE-2007-2350?
CVE-2007-2350 is a vulnerability with a CVSS score of 6.5 (MEDIUM). admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the del parameter.
How severe is CVE-2007-2350?
CVE-2007-2350 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2350?
Check the references section above for vendor advisories and patch information. Affected products include: Freepbx Freepbx.