mubix / shellshocker-pocs

Collection of Proof of Concepts and Potential Targets for #ShellShocker
MIT License
884 stars 194 forks source link

FreePBX / Asterisks #27

Open ghost opened 9 years ago

ghost commented 9 years ago

Hi,

the legacy "FreePBX ARI Framework module/Asterisk Recording Interface (ARI)" is vulnerable to shellshock:

http://community.freepbx.org/t/cve-2014-6271-shellshock-bash-exploit/24431

mubix commented 9 years ago

I didn't see a proof of concept in the post. Was one posted somewhere?