CVE Vulnerabilities

CVE-2005-3559

Published: Nov 16, 2005 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in the folder parameter.

Affected Software

Name Vendor Start Version End Version
Asterisk Digium 0.1.0 (including) 0.1.0 (including)
Asterisk Digium 0.1.1 (including) 0.1.1 (including)
Asterisk Digium 0.1.2 (including) 0.1.2 (including)
Asterisk Digium 0.1.3 (including) 0.1.3 (including)
Asterisk Digium 0.1.4 (including) 0.1.4 (including)
Asterisk Digium 0.1.5 (including) 0.1.5 (including)
Asterisk Digium 0.1.6 (including) 0.1.6 (including)
Asterisk Digium 0.1.7 (including) 0.1.7 (including)
Asterisk Digium 0.1.8 (including) 0.1.8 (including)
Asterisk Digium 0.1.9 (including) 0.1.9 (including)
Asterisk Digium 0.1.10 (including) 0.1.10 (including)
Asterisk Digium 0.1.11 (including) 0.1.11 (including)
Asterisk Digium 0.1.12 (including) 0.1.12 (including)
Asterisk Digium 0.2.0 (including) 0.2.0 (including)
Asterisk Digium 0.3.0 (including) 0.3.0 (including)
Asterisk Digium 0.4.0 (including) 0.4.0 (including)
Asterisk Digium 0.5.0 (including) 0.5.0 (including)
Asterisk Digium 0.7.0 (including) 0.7.0 (including)
Asterisk Digium 0.7.1 (including) 0.7.1 (including)
Asterisk Digium 0.7.2 (including) 0.7.2 (including)
Asterisk Digium 1.0.0 (including) 1.0.0 (including)
Asterisk Digium 1.0.1 (including) 1.0.1 (including)
Asterisk Digium 1.0.2 (including) 1.0.2 (including)
Asterisk Digium 1.0.3 (including) 1.0.3 (including)
Asterisk Digium 1.0.4 (including) 1.0.4 (including)
Asterisk Digium 1.0.5 (including) 1.0.5 (including)
Asterisk Digium 1.0.6 (including) 1.0.6 (including)
Asterisk Digium 1.0.7 (including) 1.0.7 (including)
Asterisk Digium 1.0.8 (including) 1.0.8 (including)
Asterisk Digium 1.0.9 (including) 1.0.9 (including)
Asterisk Digium 1.0_rc1 (including) 1.0_rc1 (including)
Asterisk Digium 1.0_rc2 (including) 1.0_rc2 (including)
Asterisk Digium 1.2.0_beta1 (including) 1.2.0_beta1 (including)
Asterisk Ubuntu dapper *
Asterisk Ubuntu devel *
Asterisk Ubuntu edgy *
Asterisk Ubuntu feisty *
Asterisk Ubuntu gutsy *

References