Wednesday, September 29, 2010

FreePBX: Remote Code Execution

Users of FreePBX please be advised of a Remote Code Execution vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
TWSL2010-005: FreePBX - Remote Code Execution
Finding:

The configuration interface for FreePBX is prone to a remote arbitrary code

execution on the system recordings menu. FreePBX doesn't handle file uploads

in a secure manner, allowing an attacker to manipulate the file extension

and the beginning of the uploaded file name.Read more at www.criticalwatch.com
 

No comments:

Post a Comment