CVE-2010-3490 EXPLOIT
6.5
MEDIUM · CVSS 2.0 · EPSS 9.4% (pctl 95)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a .. (dot dot) in the usersnum parameter to admin/config.php, as demonstrated by creating a .php file under the web root.
Scoring
| CVSS | 6.5 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
| EPSS | 9.39% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-09-28 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| sangoma | freepbx |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | FreePBX 2.8.0 - Recordings Interface Allows Remote Code Execution | 2010-09-24 |
References
- http://www.exploit-db.com/exploits/15098
- http://www.freepbx.org/trac/ticket/4553
- http://www.securityfocus.com/archive/1/513947/100/0/threaded
- http://www.securityfocus.com/bid/43454
- https://www.trustwave.com/spiderlabs/advisories/TWSL2010-005.txt
- http://www.exploit-db.com/exploits/15098
- http://www.freepbx.org/trac/ticket/4553
- http://www.securityfocus.com/archive/1/513947/100/0/threaded
- http://www.securityfocus.com/bid/43454
- https://www.trustwave.com/spiderlabs/advisories/TWSL2010-005.txt
→ the Explorer · watch your stack · NVD