NetGear WNDR4700 CVE-2013-3073 Symlink Directory Traversal Vulnerability
BID:59307
CVE-2013-3073 |Info
NetGear WNDR4700 CVE-2013-3073 Symlink Directory Traversal Vulnerability
| Bugtraq ID: | 59307 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3073 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2013 12:00AM |
| Updated: | Apr 17 2013 12:00AM |
| Credit: | Jacob Holcomb of Independent Security Evaluators |
| Vulnerable: |
NetGear WNDR4700 1.0.0.34 |
| Not Vulnerable: | |
Discussion
NetGear WNDR4700 CVE-2013-3073 Symlink Directory Traversal Vulnerability
NetGear WNDR4700 is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploits would allow an attacker to access files outside of the restricted directory to obtain sensitive information and perform other attacks.
NetGear WNDR4700 running firmware 1.0.0.34 is vulnerable.
NetGear WNDR4700 is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploits would allow an attacker to access files outside of the restricted directory to obtain sensitive information and perform other attacks.
NetGear WNDR4700 running firmware 1.0.0.34 is vulnerable.
Exploit / POC
NetGear WNDR4700 CVE-2013-3073 Symlink Directory Traversal Vulnerability
An attacker can exploit this issue using standard commands and readily available tools.
An attacker can exploit this issue using standard commands and readily available tools.