Netgear FM114P Wireless Firewall File Disclosure Vulnerability
BID:6807
Info
Netgear FM114P Wireless Firewall File Disclosure Vulnerability
| Bugtraq ID: | 6807 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 10 2003 12:00AM |
| Updated: | Feb 10 2003 12:00AM |
| Credit: | Discovery is credited to <[email protected]>. |
| Vulnerable: |
NetGear FM114P |
| Not Vulnerable: | |
Discussion
Netgear FM114P Wireless Firewall File Disclosure Vulnerability
Netgear FM114P Wireless Firewalls allow directory traversal using escaped character sequences. It is possible for an unauthenticated user to retrieve the firewall's configuration file by escaping from the /upnp/service directory.
Netgear FM114P Wireless Firewalls allow directory traversal using escaped character sequences. It is possible for an unauthenticated user to retrieve the firewall's configuration file by escaping from the /upnp/service directory.
Exploit / POC
Netgear FM114P Wireless Firewall File Disclosure Vulnerability
This vulnerability can be exploited using a web browser. The following proof of concept was provided:
http://<ip-or-hostname>:<port>/upnp/service/%2e%2e%2fnetgear.cfg
This vulnerability can be exploited using a web browser. The following proof of concept was provided:
http://<ip-or-hostname>:<port>/upnp/service/%2e%2e%2fnetgear.cfg
References
Netgear FM114P Wireless Firewall File Disclosure Vulnerability
References:
References: