← Back

CVE-2007-2191

nvd nist
Published: Apr 24, 2007Modified: Apr 23, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.

Affected (2)

Products: Freepbx: Freepbx
1 product
Freepbx
Configuration A
2 vulnerable · 7 platform
Vulnerable SoftwareAffected Versions
Freepbx
Version 2.2.1
Version 2.2_rc1
Running on/withPlatform Versions
Bsd
Bsd
All versions
Hp
Hp Ux
All versions
Hp
Tru64
All versions
Ibm
Aix
All versions
Linux
Linux Kernel
All versions
Santa Cruz Operation
Sco Unix
All versions
Sun
Solaris
All versions

References (14)

Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.