Vulnerability Name: | CVE-2007-6170 (CCN-38765) | ||||||||||||||||
Assigned: | 2007-11-29 | ||||||||||||||||
Published: | 2007-11-29 | ||||||||||||||||
Updated: | 2018-10-26 | ||||||||||||||||
Summary: | SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x before B.2.3.4, and C.x before C.1.0-beta6 allows remote authenticated users to execute arbitrary SQL commands via (1) ANI and (2) DNIS arguments. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P) 5.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
6.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-89 | ||||||||||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2007-6170 Source: CONFIRM Type: Patch, Vendor Advisory http://downloads.digium.com/pub/security/AST-2007-026.html Source: SUSE Type: Third Party Advisory SUSE-SR:2008:005 Source: CCN Type: SA27827 Asterisk Call Detail Record Postgres SQL Injection Source: SECUNIA Type: Third Party Advisory 27827 Source: SECUNIA Type: Third Party Advisory 27892 Source: SECUNIA Type: Third Party Advisory 29242 Source: SECUNIA Type: Third Party Advisory 29782 Source: GENTOO Type: Third Party Advisory GLSA-200804-13 Source: CCN Type: SECTRACK ID: 1019020 Asterisk Input Validation Flaw in cdr_pgsql Lets Remote Users Inject SQL Commands Source: SECTRACK Type: Third Party Advisory, VDB Entry 1019020 Source: CCN Type: AST-2007-026 SQL Injection issue in cdr_pgsql Source: DEBIAN Type: Third Party Advisory DSA-1417 Source: DEBIAN Type: DSA-1417 asterisk -- missing input sanitising Source: CCN Type: GLSA-200804-13 Asterisk: Multiple vulnerabilities Source: CCN Type: OSVDB ID: 38932 Asterisk Call Detail Record Postgres Multiple Strings SQL Injection Source: BUGTRAQ Type: Third Party Advisory, VDB Entry 20071129 AST-2007-026 - SQL Injection issue in cdr_pgsql Source: BID Type: Third Party Advisory, VDB Entry 26647 Source: CCN Type: BID-26647 Asterisk CDR_PGSQL SQL Injection Vulnerability Source: VUPEN Type: Third Party Advisory ADV-2007-4056 Source: XF Type: Third Party Advisory, VDB Entry asterisk-cdrpqsql-sql-injection(38765) Source: XF Type: UNKNOWN asterisk-cdrpqsql-sql-injection(38765) Source: SUSE Type: SUSE-SR:2008:005 SUSE Security Summary Report | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |