First published: Tue Apr 24 2007(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bsd Bsd | ||
HP HP-UX | ||
HP Tru64 | ||
IBM AIX | ||
Linux Linux kernel | ||
Santa Cruz Operation Sco Unix | ||
Sun Solaris | ||
Freepbx Freepbx | =2.2.1 | |
Freepbx Freepbx | =2.2_rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.