Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-1903
Description:admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execute arbitrary PHP code via the function and args parameters to admin/config.php.
Test IDs: 1.3.6.1.4.1.25623.1.0.103920  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-1903
Bugtraq: 20140211 [CVE-2014-1903] FreePBX 2.9 through 12 RCE (Google Search)
http://www.securityfocus.com/archive/1/531040/100/0/threaded
http://archives.neohapsis.com/archives/fulldisclosure/2014-02/0097.html
http://archives.neohapsis.com/archives/fulldisclosure/2014-02/0111.html
http://packetstormsecurity.com/files/125166/FreePBX-2.x-Code-Execution.html
http://packetstormsecurity.com/files/125215/FreePBX-2.9-Remote-Code-Execution.html
https://github.com/0x00string/oldays/blob/master/CVE-2014-1903.pl
http://osvdb.org/103240




© 1998-2025 E-Soft Inc. All rights reserved.