Vulnerabilities > CVE-2007-2191 - HTML Injection vulnerability in Freepbx 2.2.1/2.2Rc1

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.

Vulnerable Configurations

Part Description Count
OS
Bsd
1
OS
Hp
2
OS
Ibm
1
OS
Linux
1
OS
Santa_Cruz_Operation
1
OS
Sun
1
Application
Freepbx
2

Exploit-Db

descriptionFreePBX 2.2 SIP Packet Multiple HTML Injection Vulnerabilitiesa. CVE-2007-2191 . Remote exploits for multiple platform
idEDB-ID:29873
last seen2016-02-03
modified2007-04-20
published2007-04-20
reporterXenoMuta
sourcehttps://www.exploit-db.com/download/29873/
titleFreePBX 2.2 SIP Packet Multiple HTML Injection Vulnerabilities