Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Astium VOIP PBX <= 2.1 SQL Injection File Upload RCE
Vulnerability Description
A vulnerability exists in OAstium VoIP PBX astium-confweb-2.1-25399 and earlier, where improper input validation in the logon.php script allows an attacker to bypass authentication via SQL injection. Once authenticated as an administrator, the attacker can upload arbitrary PHP code through the importcompany field in import.php, resulting in remote code execution. The malicious payload is injected into /usr/local/astium/web/php/config.php and executed with root privileges by triggering a configuration reload via sudo /sbin/service astcfgd reload. Successful exploitation leads to full system compromise.
CVSS Information
N/A
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Astium VoIP PBX 安全漏洞
Vulnerability Description
Astium VoIP PBX是Astium公司的一个基于IP网络的电话交换系统。 Astium VoIP PBX astium-confweb-2.1-25399及之前版本存在安全漏洞,该漏洞源于logon.php脚本输入验证不当,可能导致SQL注入和远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A