SQL injection vulnerability in a2billing/customer/iridium_threed.php in Elastix 2.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the transactionID parameter.
                
            References
                    | Link | Resource | 
|---|---|
| http://packetstormsecurity.com/files/130698/Elastix-2.5.0-SQL-Injection.html | Exploit | 
| https://www.exploit-db.com/exploits/36305/ | Exploit | 
Configurations
                    Information
                Published : 2015-03-11 07:59
Updated : 2016-08-03 20:17
NVD link : CVE-2015-1875
Mitre link : CVE-2015-1875
JSON object : View
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
                palosanto
- elastix
 


