Vulnerable Systems:
* Astium VoIP PBX 2.1 build 25399
Astium VoIP PBX contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the logon.php not properly sanitizing user-supplied input to the 'user_name' parameter. This may allow an attacker to manipulate an SQL query that will result in bypassing authentication. Once authenticated, the attacker will have access to the application with the same privileges as an administrator account used during the authentication bypass.
Disclosure Timeline:
Vendor Informed Date :2011-08-22
Disclosure Date :2013-01-02
Exploit Publish Date :2013-01-02