Vulnerabilities > CVE-2005-3559 - Unspecified vulnerability in Digium Asterisk

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
digium
nessus
exploit available

Summary

Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in the folder parameter.

Exploit-Db

descriptionAsterisk 0.x/1.0/1.2 Voicemail Unauthorized Access Vulnerability. CVE-2005-3559. Webapps exploit for cgi platform
idEDB-ID:26475
last seen2016-02-03
modified2005-11-07
published2005-11-07
reporterAdam Pointon
sourcehttps://www.exploit-db.com/download/26475/
titleAsterisk 0.x/1.0/1.2 Voicemail Unauthorized Access Vulnerability

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-1048.NASL
descriptionSeveral problems have been discovered in Asterisk, an Open Source Private Branch Exchange (telephone control center). The Common Vulnerabilities and Exposures project identifies the following problems : - CVE-2005-3559 Adam Pointon discovered that due to missing input sanitising it is possible to retrieve recorded phone messages for a different extension. - CVE-2006-1827 Emmanouel Kellinis discovered an integer signedness error that could trigger a buffer overflow and hence allow the execution of arbitrary code.
last seen2020-06-01
modified2020-06-02
plugin id22590
published2006-10-14
reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/22590
titleDebian DSA-1048-1 : asterisk - several vulnerabilities