Описание
Asterisk Recording Interface (ARI) in Asterisk@Home before 2.8 stores recordings/includes/main.conf under the web document root with insufficient access control, which allows remote attackers to obtain password information.
Ссылки
- ExploitPatchVendor Advisory
- ExploitPatch
- Exploit
- ExploitPatchVendor Advisory
- ExploitPatch
- Exploit
Уязвимые конфигурации
Конфигурация 1Версия до 2.6 (включая)
cpe:2.3:a:asteriskathome:asteriskathome:*:*:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.10869
Средний
7.8 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Asterisk Recording Interface (ARI) in Asterisk@Home before 2.8 stores recordings/includes/main.conf under the web document root with insufficient access control, which allows remote attackers to obtain password information.
EPSS
Процентиль: 93%
0.10869
Средний
7.8 High
CVSS2
Дефекты
NVD-CWE-Other