Vulnerability Details CVE-2012-4869
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary commands via the callmenum parameter in a c action.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.849
EPSS Ranking 99.3%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2012-4869
-
cpe:2.3:a:sangoma:freepbx:-
-
cpe:2.3:a:sangoma:freepbx:2.3.0
-
cpe:2.3:a:sangoma:freepbx:2.3.0.1
-
cpe:2.3:a:sangoma:freepbx:2.3.0.2
-
cpe:2.3:a:sangoma:freepbx:2.3.0.3
-
cpe:2.3:a:sangoma:freepbx:2.4.0
-
cpe:2.3:a:sangoma:freepbx:2.4.0.1
-
cpe:2.3:a:sangoma:freepbx:2.4.0.2
-
cpe:2.3:a:sangoma:freepbx:2.4.0.3
-
cpe:2.3:a:sangoma:freepbx:2.4.0.4
-
cpe:2.3:a:sangoma:freepbx:2.5.0
-
cpe:2.3:a:sangoma:freepbx:2.5.0.1
-
cpe:2.3:a:sangoma:freepbx:2.5.0.2
-
cpe:2.3:a:sangoma:freepbx:2.5.0.3
-
cpe:2.3:a:sangoma:freepbx:2.5.0.4
-
cpe:2.3:a:sangoma:freepbx:2.5.1.0
-
cpe:2.3:a:sangoma:freepbx:2.5.1.1
-
cpe:2.3:a:sangoma:freepbx:2.5.1.2
-
cpe:2.3:a:sangoma:freepbx:2.6.0
-
cpe:2.3:a:sangoma:freepbx:2.6.0.1
-
cpe:2.3:a:sangoma:freepbx:2.7.0
-
cpe:2.3:a:sangoma:freepbx:2.7.0.2
-
cpe:2.3:a:sangoma:freepbx:2.8.0
-
cpe:2.3:a:sangoma:freepbx:2.8.0.1
-
cpe:2.3:a:sangoma:freepbx:2.9
-
cpe:2.3:a:sangoma:freepbx:2.9.0