Title : Asterisk "vmail.cgi" Script Remote Directory Traversal Vulnerability VUPEN ID : VUPEN/ADV-2005-2346 CVE ID : CVE-2005-3559
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-11-08
Technical Description
A vulnerability has been identified in Asterisk, which may be exploited by malicious users to retrieve arbitrary files. This flaw is due to an input validation error in the "vmail.cgi" script that does not properly handle a specially crafted "folder" parameter, which may be exploited by authenticated attackers to gain knowledge of other users' messages ("wav" files).