CVE-2012-4870 | FreePBX 2.9 /index_amp.php context cross site scripting (Unofficial Patch / EDB-18649)
A vulnerability was found in FreePBX 2.9. It has been classified as critical. Affected is an unknown function of the file /index_amp.php. The manipulation of the argument context leads to cross site scripting.
This vulnerability is traded as CVE-2012-4870. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.