Vulnerabilities
Vulnerable Software
Freepbx:  >> Freepbx  >> 2.5  Security Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote attackers to hijack the authentication of admins for requests that create a new admin account or have unspecified other impact.
CVSS Score
6.8
EPSS Score
0.001
Published
2009-05-28
FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
CVSS Score
5.0
EPSS Score
0.003
Published
2009-05-28


Contact Us

Shodan ® - All rights reserved