Vulnerabilities > CVE-2006-6244 - Input Validation vulnerability in FreePBX

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
coalescent-systems

Summary

Coalescent Systems freePBX (formerly Asterisk Management Portal) before 2.2.0rc1 allows attackers to execute arbitrary commands via shell metacharacters in (1) CALLERID(name) or (2) CALLERID(number). This vulnerability is addressed in the following product release: Coalescent Systems, freePBX, 2.2.0rc1

Vulnerable Configurations

Part Description Count
Application
Coalescent_Systems
1