registry.pl in Fonality Trixbox 2.0 PBX products, when running in...
Vulnerability Description
registry.pl in Fonality Trixbox 2.0 PBX products, when running in certain environments, reads and executes a set of commands from a remote web site without sufficiently validating the origin of the commands, which allows remote attackers to disable trixbox and execute arbitrary commands via a DNS spoofing attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-6424
Credits & Attribution
No credits recorded in the NVD database.
References
- http://voipsa.org/pipermail/voipsec_voipsa.org/2007-December/002528.html
- http://voipsa.org/pipermail/voipsec_voipsa.org/2007-December/002522.html
- http://voipsa.org/pipermail/voipsec_voipsa.org/2007-December/002533.html
- http://www.trixbox.org/forums/trixbox-forums/open-discussion/trixbox-phones-home
- http://voipsa.org/blog/2007/12/17/trixbox-contains-phone-home-code-to-retrieve-arbitrary-commands-to-execute/
- http://osvdb.org/44136
- http://www.superunknown.org/pivot/entry.php?id=15
More from netfortris
View All →Affected Vendor
netfortris
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.