6.5
CVSSv2

CVE-2007-6170

Published: 30/11/2007 Updated: 26/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x prior to 1.4.15, 1.2.x prior to 1.2.25, B.x before B.2.3.4, and C.x before C.1.0-beta6 allows remote authenticated users to execute arbitrary SQL commands via (1) ANI and (2) DNIS arguments.

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk

digium asterisk c.1.0

debian debian linux 3.1

debian debian linux 4.0

Vendor Advisories

Tilghman Lesher discovered that the logging engine of Asterisk, a free software PBX and telephony toolkit, performs insufficient sanitising of call-related data, which may lead to SQL injection For the old stable distribution (sarge), this problem has been fixed in version 1:107dfsg1-2sarge6 For the stable distribution (etch), this problem ha ...