CVE Vulnerabilities

CVE-2005-3559

Published: Nov 16, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in the folder parameter.

Affected Software

NameVendorStart VersionEnd Version
AsteriskDigium0.1.0 (including)0.1.0 (including)
AsteriskDigium0.1.1 (including)0.1.1 (including)
AsteriskDigium0.1.2 (including)0.1.2 (including)
AsteriskDigium0.1.3 (including)0.1.3 (including)
AsteriskDigium0.1.4 (including)0.1.4 (including)
AsteriskDigium0.1.5 (including)0.1.5 (including)
AsteriskDigium0.1.6 (including)0.1.6 (including)
AsteriskDigium0.1.7 (including)0.1.7 (including)
AsteriskDigium0.1.8 (including)0.1.8 (including)
AsteriskDigium0.1.9 (including)0.1.9 (including)
AsteriskDigium0.1.10 (including)0.1.10 (including)
AsteriskDigium0.1.11 (including)0.1.11 (including)
AsteriskDigium0.1.12 (including)0.1.12 (including)
AsteriskDigium0.2.0 (including)0.2.0 (including)
AsteriskDigium0.3.0 (including)0.3.0 (including)
AsteriskDigium0.4.0 (including)0.4.0 (including)
AsteriskDigium0.5.0 (including)0.5.0 (including)
AsteriskDigium0.7.0 (including)0.7.0 (including)
AsteriskDigium0.7.1 (including)0.7.1 (including)
AsteriskDigium0.7.2 (including)0.7.2 (including)
AsteriskDigium1.0.0 (including)1.0.0 (including)
AsteriskDigium1.0.1 (including)1.0.1 (including)
AsteriskDigium1.0.2 (including)1.0.2 (including)
AsteriskDigium1.0.3 (including)1.0.3 (including)
AsteriskDigium1.0.4 (including)1.0.4 (including)
AsteriskDigium1.0.5 (including)1.0.5 (including)
AsteriskDigium1.0.6 (including)1.0.6 (including)
AsteriskDigium1.0.7 (including)1.0.7 (including)
AsteriskDigium1.0.8 (including)1.0.8 (including)
AsteriskDigium1.0.9 (including)1.0.9 (including)
AsteriskDigium1.0_rc1 (including)1.0_rc1 (including)
AsteriskDigium1.0_rc2 (including)1.0_rc2 (including)
AsteriskDigium1.2.0_beta1 (including)1.2.0_beta1 (including)
AsteriskUbuntudapper*
AsteriskUbuntudevel*
AsteriskUbuntuedgy*
AsteriskUbuntufeisty*
AsteriskUbuntugutsy*

References