Vulnerability Description
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execute arbitrary PHP code via the function and args parameters to admin/config.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freepbx | Freepbx | 2.10 |
| Sangoma | Freepbx | 2.9 |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/fulldisclosure/2014-02/0097.html
- http://archives.neohapsis.com/archives/fulldisclosure/2014-02/0111.html
- http://code.freepbx.org/changelog/FreePBX_Framework?cs=a29382efeb293ef4f42aa9b84
- http://code.freepbx.org/changelog/FreePBX_SVN?cs=16429
- http://issues.freepbx.org/browse/FREEPBX-7117Vendor Advisory
- http://issues.freepbx.org/browse/FREEPBX-7123Vendor Advisory
- http://osvdb.org/103240
- http://packetstormsecurity.com/files/125166/FreePBX-2.x-Code-Execution.html
- http://packetstormsecurity.com/files/125215/FreePBX-2.9-Remote-Code-Execution.ht
- http://www.freepbx.org/news/2014-02-06/security-vulnerability-notice
- http://www.securityfocus.com/archive/1/531040/100/0/threaded
- https://github.com/0x00string/oldays/blob/master/CVE-2014-1903.pl
- http://archives.neohapsis.com/archives/fulldisclosure/2014-02/0097.html
- http://archives.neohapsis.com/archives/fulldisclosure/2014-02/0111.html
- http://code.freepbx.org/changelog/FreePBX_Framework?cs=a29382efeb293ef4f42aa9b84
FAQ
What is CVE-2014-1903?
CVE-2014-1903 is a vulnerability with a CVSS score of 7.5 (HIGH). admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the AP...
How severe is CVE-2014-1903?
CVE-2014-1903 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-1903?
Check the references section above for vendor advisories and patch information. Affected products include: Freepbx Freepbx, Sangoma Freepbx.