CVE-2006-7107 – Coalescent Systems freePBX Remote Code Execution

Description

PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the amp_conf[AMPWEBROOT] parameter.


Vulnerability Information

  • Product / Framework: Coalescent_systems
  • Vendor Domain: sourceforge.net
  • Vulnerability Type: SQL Injection
  • CVE Details: View Full CVE Details →