CVE Vulnerabilities

CVE-2005-3559

Published: Nov 16, 2005 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in the folder parameter.

Affected Software

Name Vendor Start Version End Version
Asterisk Digium 0.1.0 (including) 0.1.0 (including)
Asterisk Digium 0.1.1 (including) 0.1.1 (including)
Asterisk Digium 0.1.2 (including) 0.1.2 (including)
Asterisk Digium 0.1.3 (including) 0.1.3 (including)
Asterisk Digium 0.1.4 (including) 0.1.4 (including)
Asterisk Digium 0.1.5 (including) 0.1.5 (including)
Asterisk Digium 0.1.6 (including) 0.1.6 (including)
Asterisk Digium 0.1.7 (including) 0.1.7 (including)
Asterisk Digium 0.1.8 (including) 0.1.8 (including)
Asterisk Digium 0.1.9 (including) 0.1.9 (including)
Asterisk Digium 0.1.10 (including) 0.1.10 (including)
Asterisk Digium 0.1.11 (including) 0.1.11 (including)
Asterisk Digium 0.1.12 (including) 0.1.12 (including)
Asterisk Digium 0.2.0 (including) 0.2.0 (including)
Asterisk Digium 0.3.0 (including) 0.3.0 (including)
Asterisk Digium 0.4.0 (including) 0.4.0 (including)
Asterisk Digium 0.5.0 (including) 0.5.0 (including)
Asterisk Digium 0.7.0 (including) 0.7.0 (including)
Asterisk Digium 0.7.1 (including) 0.7.1 (including)
Asterisk Digium 0.7.2 (including) 0.7.2 (including)
Asterisk Digium 1.0.0 (including) 1.0.0 (including)
Asterisk Digium 1.0.1 (including) 1.0.1 (including)
Asterisk Digium 1.0.2 (including) 1.0.2 (including)
Asterisk Digium 1.0.3 (including) 1.0.3 (including)
Asterisk Digium 1.0.4 (including) 1.0.4 (including)
Asterisk Digium 1.0.5 (including) 1.0.5 (including)
Asterisk Digium 1.0.6 (including) 1.0.6 (including)
Asterisk Digium 1.0.7 (including) 1.0.7 (including)
Asterisk Digium 1.0.8 (including) 1.0.8 (including)
Asterisk Digium 1.0.9 (including) 1.0.9 (including)
Asterisk Digium 1.0_rc1 (including) 1.0_rc1 (including)
Asterisk Digium 1.0_rc2 (including) 1.0_rc2 (including)
Asterisk Digium 1.2.0_beta1 (including) 1.2.0_beta1 (including)

References