7.8
CVSSv2

CVE-2006-2020

Published: 25/04/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Asterisk Recording Interface (ARI) in Asterisk@Home prior to 2.8 stores recordings/includes/main.conf under the web document root with insufficient access control, which allows remote malicious users to obtain password information.

Vulnerable Product Search on Vulmon Subscribe to Product

asteriskathome asteriskathome

Exploits

source: wwwsecurityfocuscom/bid/17641/info Asterisk Recording Interface is prone to an information-disclosure vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input An attacker can exploit this vulnerability to retrieve arbitrary MP3, WAV, and GSM files from the vulnerable system in th ...