Lucene search

K
cveMitreCVE-2007-2191
HistoryApr 24, 2007 - 5:19 p.m.

CVE-2007-2191

2007-04-2417:19:00
mitre
web.nvd.nist.gov
34
cve-2007-2191
cross-site scripting
xss
freepbx 2.2.x
web script injection
html injection
remote attack
sip protocol

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

5.7

Confidence

High

EPSS

0.166

Percentile

96.1%

Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.

Affected configurations

Nvd
Node
bsdbsd
OR
hphp-ux
OR
hptru64
OR
ibmaix
OR
linuxlinux_kernel
OR
santa_cruz_operationsco_unix
OR
sunsolaris
AND
freepbxfreepbxMatch2.2.1
OR
freepbxfreepbxMatch2.2_rc1
VendorProductVersionCPE
bsdbsd*cpe:2.3:o:bsd:bsd:*:*:*:*:*:*:*:*
hphp-ux*cpe:2.3:o:hp:hp-ux:*:*:*:*:*:*:*:*
hptru64*cpe:2.3:o:hp:tru64:*:*:*:*:*:*:*:*
ibmaix*cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
linuxlinux_kernel*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
santa_cruz_operationsco_unix*cpe:2.3:o:santa_cruz_operation:sco_unix:*:*:*:*:*:*:*:*
sunsolaris*cpe:2.3:o:sun:solaris:*:*:*:*:*:*:*:*
freepbxfreepbx2.2.1cpe:2.3:a:freepbx:freepbx:2.2.1:*:*:*:*:*:*:*
freepbxfreepbx2.2_rc1cpe:2.3:a:freepbx:freepbx:2.2_rc1:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

5.7

Confidence

High

EPSS

0.166

Percentile

96.1%