← Back

CVE-2014-7235

nvd nist
Published: Oct 7, 2014Modified: May 6, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth cookie, related to the PHP unserialize function, as exploited in the wild in September 2014.

Affected (22)

1 product
Freepbx
1 product
Freepbx
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Freepbx
Version 2.10.0.0
Version 2.10.0.10
Version 2.10.0.1
Version 2.10.0.2
Version 2.10.0.3
Version 2.10.0.4
Version 2.10.0.5
Version 2.10.0.6
Version 2.10.0.7
Version 2.10.0.8
Version 2.10.0.9
Version 2.11.1.0
Version 2.11.1.1
Version 2.11.1.2
Version 2.11.1.3
Version 2.11.1.4
Sangoma
Up to 2.9.0.8
Version 2.11.0.0
Version 2.11.0.1
Version 2.11.0.2
Version 2.11.0.3
Version 2.11.0.4

Timeline

No history available yet.