>> Asterisk Call Detail Record Postgres Logging SQL Injection Vulnerability
Title : Asterisk Call Detail Record Postgres Logging SQL Injection Vulnerability VUPEN ID : VUPEN/ADV-2007-4056 CVE ID : CVE-2007-6170
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-03
Technical Description
A vulnerability has been identified in Asterisk, which could be exploited by authenticated attackers to execute arbitrary SQL queries. This issue is caused by an input validation error in the Call Detail Record Postgres logging engine when processing the "ANI" and "DNIS" strings, which could be exploited by malicious users to conduct SQL injection attacks.
Note : The affected module is disabled by default.