CVE-2007-5488: SQL Injection
Published Oct 17, 2007
·Updated
Multiple SQL injection vulnerabilities in cdraddonmysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to execute arbitrary SQL commands via the (1) source and (2) destination numbers, and probably (3) SIP URI, when inserting a record.
Affected Software
2 affected components
Asterisk Asterisk-Addons<=1.4.3
Asterisk Asterisk-Addons<=1.2.7
Event History
Oct 17, 2007
CVE Published
11:17 PM
Oct 18, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5488?
CVE-2007-5488 has a high severity rating due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2007-5488?
To fix CVE-2007-5488, upgrade the Asterisk-Addons to version 1.2.8 or later, or 1.4.4 or later.
3
Which versions are affected by CVE-2007-5488?
CVE-2007-5488 affects Asterisk-Addons versions before 1.2.8 and 1.4.x before 1.4.4.
4
What types of SQL injection are involved in CVE-2007-5488?
CVE-2007-5488 allows SQL injection through the source and destination numbers, and possibly the SIP URI.
5
Can CVE-2007-5488 be exploited by remote attackers?
Yes, CVE-2007-5488 can be exploited by remote attackers to execute arbitrary SQL commands.