Unrated severityNVD Advisory· Published Dec 18, 2007· Updated Apr 23, 2026
CVE-2007-6424
CVE-2007-6424
Description
registry.pl in Fonality Trixbox 2.0 PBX products, when running in certain environments, reads and executes a set of commands from a remote web site without sufficiently validating the origin of the commands, which allows remote attackers to disable trixbox and execute arbitrary commands via a DNS spoofing attack.
Affected products
1- cpe:2.3:a:netfortris:trixbox:2.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.superunknown.org/pivot/entry.phpnvdExploitURL Repurposed
- osvdb.org/44136nvd
- voipsa.org/blog/2007/12/17/trixbox-contains-phone-home-code-to-retrieve-arbitrary-commands-to-execute/nvd
- voipsa.org/pipermail/voipsec_voipsa.org/2007-December/002522.htmlnvd
- voipsa.org/pipermail/voipsec_voipsa.org/2007-December/002528.htmlnvd
- voipsa.org/pipermail/voipsec_voipsa.org/2007-December/002533.htmlnvd
- www.trixbox.org/forums/trixbox-forums/open-discussion/trixbox-phones-homenvd
News mentions
0No linked articles in our index yet.