First published: Tue Sep 28 2010(Updated: )
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a .. (dot dot) in the usersnum parameter to admin/config.php, as demonstrated by creating a .php file under the web root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreePBX | <=2.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3490 is classified as a high-severity vulnerability due to its potential for arbitrary file creation by authenticated users.
To fix CVE-2010-3490, upgrade to a version of FreePBX later than 2.8.0 that patches this vulnerability.
CVE-2010-3490 affects administrators using FreePBX 2.8.0 and earlier versions.
CVE-2010-3490 is a directory traversal vulnerability that allows unauthorized file access.
Yes, CVE-2010-3490 can be exploited remotely by authenticated administrators through manipulated parameters.