Total vulnerabilities in the database
admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the del parameter.
CVSS v2:
No CWE or OWASP classifications available.