Asterisk Project Security Advisory – Source and destination numbers for a given call are not correctly escaped by the cdr_addon_mysql module in Asterisk, allowing for SQL injection attacks.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60185/AST-2007-023.txt
Source: https://packetstormsecurity.com/files/60185/AST-2007-023.txt.html