Lucene search

K
nvd[email protected]NVD:CVE-2010-3490
HistorySep 28, 2010 - 6:00 p.m.

CVE-2010-3490

2010-09-2818:00:03
CWE-22
web.nvd.nist.gov

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

6.2 Medium

AI Score

Confidence

Low

0.873 High

EPSS

Percentile

98.7%

Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a … (dot dot) in the usersnum parameter to admin/config.php, as demonstrated by creating a .php file under the web root.

Affected configurations

NVD
Node
sangomafreepbxRange2.8.0

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

6.2 Medium

AI Score

Confidence

Low

0.873 High

EPSS

Percentile

98.7%