Vulnerability Details CVE-2010-3490
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a .. (dot dot) in the usersnum parameter to admin/config.php, as demonstrated by creating a .php file under the web root.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.09
EPSS Ranking 92.2%
CVSS Severity
CVSS v2 Score 6.5
Products affected by CVE-2010-3490
-
cpe:2.3:a:sangoma:freepbx:-
-
cpe:2.3:a:sangoma:freepbx:2.3.0
-
cpe:2.3:a:sangoma:freepbx:2.3.0.1
-
cpe:2.3:a:sangoma:freepbx:2.3.0.2
-
cpe:2.3:a:sangoma:freepbx:2.3.0.3
-
cpe:2.3:a:sangoma:freepbx:2.4.0
-
cpe:2.3:a:sangoma:freepbx:2.4.0.1
-
cpe:2.3:a:sangoma:freepbx:2.4.0.2
-
cpe:2.3:a:sangoma:freepbx:2.4.0.3
-
cpe:2.3:a:sangoma:freepbx:2.4.0.4
-
cpe:2.3:a:sangoma:freepbx:2.5.0
-
cpe:2.3:a:sangoma:freepbx:2.5.0.1
-
cpe:2.3:a:sangoma:freepbx:2.5.0.2
-
cpe:2.3:a:sangoma:freepbx:2.5.0.3
-
cpe:2.3:a:sangoma:freepbx:2.5.0.4
-
cpe:2.3:a:sangoma:freepbx:2.5.1.0
-
cpe:2.3:a:sangoma:freepbx:2.5.1.1
-
cpe:2.3:a:sangoma:freepbx:2.5.1.2
-
cpe:2.3:a:sangoma:freepbx:2.6.0
-
cpe:2.3:a:sangoma:freepbx:2.6.0.1
-
cpe:2.3:a:sangoma:freepbx:2.7.0
-
cpe:2.3:a:sangoma:freepbx:2.7.0.2
-
cpe:2.3:a:sangoma:freepbx:2.8.0