CVE-2010-3490: Path Traversal
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a .. (dot dot) in the usersnum parameter to admin/config.php, as demonstrated by creating a .php file under the web root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3490?
CVE-2010-3490 is classified as a high-severity vulnerability due to its potential for arbitrary file creation by authenticated users.
How do I fix CVE-2010-3490?
To fix CVE-2010-3490, upgrade to a version of FreePBX later than 2.8.0 that patches this vulnerability.
Who is affected by CVE-2010-3490?
CVE-2010-3490 affects administrators using FreePBX 2.8.0 and earlier versions.
What type of vulnerability is CVE-2010-3490?
CVE-2010-3490 is a directory traversal vulnerability that allows unauthorized file access.
Can CVE-2010-3490 be exploited remotely?
Yes, CVE-2010-3490 can be exploited remotely by authenticated administrators through manipulated parameters.