CVE-2015-1875 | Palosanto Elastix up to 2.5.0 Billing iridium_threed.php transactionID sql injection (File 130698/Ela / EDB-36305)
A vulnerability classified as critical was found in Palosanto Elastix up to 2.5.0. Affected by this vulnerability is an unknown functionality of the file a2billing/customer/iridium_threed.php of the component Billing. The manipulation of the argument transactionID leads to sql injection.
This vulnerability is known as CVE-2015-1875. The attack can be launched remotely. Furthermore, there is an exploit available.