7.5
CVSSv2

CVE-2015-1875

Published: 11/03/2015 Updated: 04/08/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in a2billing/customer/iridium_threed.php in Elastix 2.5.0 and previous versions allows remote malicious users to execute arbitrary SQL commands via the transactionID parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

palosanto elastix

Exploits

# Title: Elastix v2x Blind SQL Injection Vulnerability # Author: Ahmed Aboul-Ela # Twitter: twittercom/aboul3la # Vendor : wwwelastixorg # Version: v250 and prior versions should be affected too - Vulnerable Source Code snippet in "a2billing/customer/iridium_threedphp": <?php [] line 5: getpost_ifset (array('tr ...