Coalescent Systems freePBX (formerly Asterisk Management Portal) before 2.2.0rc1 allows attackers to execute arbitrary commands via shell metacharacters in (1) CALLERID(name) or (2) CALLERID(number).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freepbx | Coalescent_systems | * | 2.1.3 (including) |