module
FreePBX 2.10.0 / 2.9.0 callmenum Remote Code Execution
Disclosed | Created |
---|---|
2012-03-20 | 2018-05-30 |
Disclosed
2012-03-20
Created
2018-05-30
Description
This module exploits FreePBX version 2.10.0,2.9.0 and possibly older.
Due to the way callme_page.php handles the 'callmenum' parameter, it
is possible to inject code to the '$channel' variable in function
callme_startcall in order to gain remote code execution.
Please note in order to use this module properly, you must know the
extension number, which can be enumerated or bruteforced, or you may
try some of the default extensions such as 0 or 200. Also, the call
has to be answered (or go to voice).
Tested on both Elastix and FreePBX ISO image installs.
Due to the way callme_page.php handles the 'callmenum' parameter, it
is possible to inject code to the '$channel' variable in function
callme_startcall in order to gain remote code execution.
Please note in order to use this module properly, you must know the
extension number, which can be enumerated or bruteforced, or you may
try some of the default extensions such as 0 or 200. Also, the call
has to be answered (or go to voice).
Tested on both Elastix and FreePBX ISO image installs.
Authors
muts
Martin Tschirsich
Martin Tschirsich
Platform
Unix
Architectures
cmd
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.