Thomson SpeedTouch 585 'user.ini' Arbitrary File Download Vulnerability
BID:43123
Info
Thomson SpeedTouch 585 'user.ini' Arbitrary File Download Vulnerability
| Bugtraq ID: | 43123 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2009 12:00AM |
| Updated: | Aug 13 2009 12:00AM |
| Credit: | aBo MoHaMeD |
| Vulnerable: |
Thomson SpeedTouch 585 6.2.29 .2 firmware |
| Not Vulnerable: | |
Discussion
Thomson SpeedTouch 585 'user.ini' Arbitrary File Download Vulnerability
Thomson SpeedTouch 585 is prone to a vulnerability that lets attackers download arbitrary files. The issue occurs because the device fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the device. Information harvested may aid in launching further attacks.
Thomson SpeedTouch 585 Firmware 6.2.29.2 is vulnerable; other versions may also be affected.
Thomson SpeedTouch 585 is prone to a vulnerability that lets attackers download arbitrary files. The issue occurs because the device fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the device. Information harvested may aid in launching further attacks.
Thomson SpeedTouch 585 Firmware 6.2.29.2 is vulnerable; other versions may also be affected.
Exploit / POC
Thomson SpeedTouch 585 'user.ini' Arbitrary File Download Vulnerability
An attacker can exploit this issue via a browser.
An attacker can exploit this issue via a browser.
Solution / Fix
Thomson SpeedTouch 585 'user.ini' Arbitrary File Download Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Thomson SpeedTouch 585 'user.ini' Arbitrary File Download Vulnerability
References:
References:
- SpeedTouch 585 Homepage (Thomson)