Asterisk Recording Interface (ARI) in Asterisk@Home before 2.8 stores recordings/includes/main.conf under the web document root with insufficient access control, which allows remote attackers to obtain password information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Asteriskathome | Asteriskathome | * | 2.6 (including) |