CVE-2007-2350: Medium severity FreePBX FreePBX vulnerability
Published Apr 30, 2007
·Updated
admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the del parameter.
Affected Software
1 affected component
FreePBX FreePBX<=2.2.1
Event History
Apr 30, 2007
CVE Published
10:19 PM
May 1, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2350?
CVE-2007-2350 is considered a high severity vulnerability due to the risk of arbitrary command execution.
2
How do I fix CVE-2007-2350?
To remediate CVE-2007-2350, update FreePBX to version 2.2.2 or later, which addresses this vulnerability.
3
Who is affected by CVE-2007-2350?
CVE-2007-2350 affects authenticated administrators using FreePBX version 2.2.x.
4
What can an attacker do with CVE-2007-2350?
An attacker can execute arbitrary commands on the server by exploiting the del parameter in the music-on-hold module.
5
Is CVE-2007-2350 still a threat today?
While CVE-2007-2350 was discovered in 2007, it remains a threat for systems that have not been updated beyond version 2.2.1.