CVE-2012-4869: Code Injection
Published Sep 6, 2012
·Updated
The callmestartcall function in recordings/misc/callmepage.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary commands via the callmenum parameter in a c action.
Affected Software
2 affected components
Sangoma FreePBX <=2.10
Sangoma FreePBX =2.9
Event History
Sep 6, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4869?
CVE-2012-4869 has a critical severity rating as it allows remote command execution on affected FreePBX systems.
2
How do I fix CVE-2012-4869?
To mitigate CVE-2012-4869, you should upgrade your FreePBX installation to version 2.11 or later.
3
Which versions of FreePBX are affected by CVE-2012-4869?
CVE-2012-4869 affects FreePBX versions 2.9 and 2.10, as well as earlier versions.
4
What type of vulnerability is CVE-2012-4869?
CVE-2012-4869 is a remote command execution vulnerability.
5
Can CVE-2012-4869 affect the security of my FreePBX installation?
Yes, CVE-2012-4869 can significantly compromise the security of your FreePBX installation by allowing attackers to execute arbitrary commands.