This exploit demonstrates an unauthenticated SQL injection vulnerability in FreePBX 13.0.35 via the 'display' parameter, which is passed unsanitized to a SQL query. The PoC includes a time-based blind SQL injection example.
Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:FreePBX 13.0.35
No auth needed
Prerequisites:Network access to the target FreePBX instance