peter bassill · operator
$ cve CVE-2010-3490 JSON

CVE-2010-3490 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 9.4% (pctl 95)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a .. (dot dot) in the usersnum parameter to admin/config.php, as demonstrated by creating a .php file under the web root.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS9.39% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2010-09-28
Last modified2026-06-16

Affected (1)

VendorProduct
sangomafreepbx

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD