First published: Mon Apr 30 2007(Updated: )
admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the del parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreePBX | <=2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2350 is considered a high severity vulnerability due to the risk of arbitrary command execution.
To remediate CVE-2007-2350, update FreePBX to version 2.2.2 or later, which addresses this vulnerability.
CVE-2007-2350 affects authenticated administrators using FreePBX version 2.2.x.
An attacker can execute arbitrary commands on the server by exploiting the del parameter in the music-on-hold module.
While CVE-2007-2350 was discovered in 2007, it remains a threat for systems that have not been updated beyond version 2.2.1.