OSVDB ID: 35315

Title: freePBX Log Injection asterisk-full-log.php XSS

Info

Disclosure

Apr 19, 2007

Discovery

Apr 19, 2007

Dates

Exploit

Apr 19, 2007

Solution

Unknown

Description

Persistent cross site scripting is possible in FreePBX 2.2.x due to no escaping of html code in the Log monitor module for the admin web interface.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Upgrade
OSVDB: Web Related

Solution

Upgrade to version 2.3 or higher, as it has been reported to fix this vulnerability.

Products

Unknown or Incomplete

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/35315