MEDIUM · 6.5

CVE-2010-3490

Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to cr...

Vulnerability Description

Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a .. (dot dot) in the usersnum parameter to admin/config.php, as demonstrated by creating a .php file under the web root.

CVSS Score

6.5

MEDIUM

AV:N/AC:L/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
SangomaFreepbx<= 2.8.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-3490?

CVE-2010-3490 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to cr...

How severe is CVE-2010-3490?

CVE-2010-3490 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-3490?

Check the references section above for vendor advisories and patch information. Affected products include: Sangoma Freepbx.