CVE-2003-0779 — SQL Injection in Asterisk
4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.0%
top 91.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 22
Latest updateApr 29
Description
SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a CallerID string.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages3 packages
🔴Vulnerability Details
2GHSA▶
GHSA-8q43-h274-m6cf: SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a↗2022-04-29
OSV▶
CVE-2003-0779: SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a↗2003-09-22
📋Vendor Advisories
1Debian▶
CVE-2003-0779: asterisk - SQL injection vulnerability in the Call Detail Record (CDR) logging functionalit...↗2003