Files
CVEs-PoC/2007/CVE-2007-6424.md
T
2024-06-18 02:51:15 +02:00

19 lines
882 B
Markdown

### [CVE-2007-6424](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6424)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
registry.pl in Fonality Trixbox 2.0 PBX products, when running in certain environments, reads and executes a set of commands from a remote web site without sufficiently validating the origin of the commands, which allows remote attackers to disable trixbox and execute arbitrary commands via a DNS spoofing attack.
### POC
#### Reference
- http://voipsa.org/pipermail/voipsec_voipsa.org/2007-December/002528.html
- http://voipsa.org/pipermail/voipsec_voipsa.org/2007-December/002533.html
#### Github
No PoCs found on GitHub currently.