Vulnerabilities > CVE-2007-2191 - Unspecified vulnerability in Freepbx 2.2.1/2.2Rc1

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
freepbx
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.

Vulnerable Configurations

Part Description Count
OS
Bsd
1
OS
Hp
2
OS
Ibm
1
OS
Linux
1
OS
Santa_Cruz_Operation
1
OS
Sun
1
Application
Freepbx
2

Exploit-Db

descriptionFreePBX 2.2 SIP Packet Multiple HTML Injection Vulnerabilitiesa. CVE-2007-2191 . Remote exploits for multiple platform
idEDB-ID:29873
last seen2016-02-03
modified2007-04-20
published2007-04-20
reporterXenoMuta
sourcehttps://www.exploit-db.com/download/29873/
titleFreePBX 2.2 SIP Packet Multiple HTML Injection Vulnerabilities