4.3
CVSSv2

CVE-2009-1801

Published: 28/05/2009 Updated: 10/12/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote malicious users to inject arbitrary web script or HTML via the (1) display parameter to reports.php, the (2) order and (3) extdisplay parameters to config.php, and the (4) sort parameter to recordings/index.php. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

sangoma freepbx 2.5.0

freepbx freepbx 2.4.0_beta2

freepbx freepbx 2.5.1

freepbx freepbx 2.5.2

freepbx freepbx 2.5.0rc3

freepbx freepbx 2.4.1

sangoma freepbx 2.4.0

freepbx freepbx 2.5.0rc2

freepbx freepbx 2.5.0_beta1

freepbx freepbx 2.4.0_beta1

freepbx freepbx 2.4