CVE-2005-3559
EPSS 5.5%asterisk - several vulnerabilities
Published: 11/16/2005Modified: 4/28/2026
Description
Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in the folder parameter.
Affected packages (2)
- Debian/asteriskfrom 0, < 1:1.2.7.1.dfsg-2
- Debian/asteriskfrom 0, < 0.1.11-3woody1