PT-2007-7276 · Fonality · Fonality Trixbox

CVE-2007-6424

·

Publicado

2007-12-18

·

Atualizado

2024-02-14

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Fonality Trixbox version 2.0
Description The issue allows remote attackers to execute arbitrary commands via a DNS spoofing attack, as the registry.pl script reads and executes commands from a remote web site without proper validation. This can lead to the disabling of trixbox.
Recommendations For Fonality Trixbox version 2.0, consider restricting access to the registry.pl script until a proper fix is available, and ensure that the environment in which it is running is secure to minimize the risk of DNS spoofing attacks.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6424

Produtos afetados

Fonality Trixbox