ID

VAR-200803-0001


CVE

CVE-2007-6702


TITLE

Rooter VDSL Device goform/QuickStart_c0 Password acquisition vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2008-002560

DESCRIPTION

goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows remote attackers to obtain this password by reading the HTML source, a different vulnerability than CVE-2002-1603. GoAhead WebServer is prone to a remote security vulnerability. GoAhead WebServer is a small and exquisite embedded Web server of American Embedthis Company, which supports embedding in various devices and applications

Trust: 1.98

sources: NVD: CVE-2007-6702 // JVNDB: JVNDB-2008-002560 // BID: 85230 // VULHUB: VHN-30064

AFFECTED PRODUCTS

vendor:goaheadmodel:fs4104-aw devicescope: - version: -

Trust: 1.4

vendor:goaheadmodel:webserverscope: - version: -

Trust: 1.4

vendor:goaheadmodel:fs4104-aw devicescope:eqversion:*

Trust: 1.0

vendor:goaheadmodel:webserverscope:eqversion:*

Trust: 1.0

vendor:goaheadmodel:software goahead webserverscope:eqversion:0

Trust: 0.3

vendor:goaheadmodel:software fs4104-aw devicescope:eqversion:0

Trust: 0.3

sources: BID: 85230 // JVNDB: JVNDB-2008-002560 // CNNVD: CNNVD-200803-024 // NVD: CVE-2007-6702

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-6702
value: MEDIUM

Trust: 1.0

NVD: CVE-2007-6702
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200803-024
value: MEDIUM

Trust: 0.6

VULHUB: VHN-30064
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2007-6702
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-30064
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-30064 // JVNDB: JVNDB-2008-002560 // CNNVD: CNNVD-200803-024 // NVD: CVE-2007-6702

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-30064 // JVNDB: JVNDB-2008-002560 // NVD: CVE-2007-6702

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200803-024

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-200803-024

CONFIGURATIONS

sources: JVNDB: JVNDB-2008-002560

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-30064

PATCH

title:Top Pageurl:http://www.oracle.com/us/corporate/acquisitions/goahead/index.html

Trust: 0.8

sources: JVNDB: JVNDB-2008-002560

EXTERNAL IDS

db:NVDid:CVE-2007-6702

Trust: 2.8

db:EXPLOIT-DBid:4744

Trust: 2.0

db:OSVDBid:43168

Trust: 1.7

db:XFid:39149

Trust: 0.9

db:JVNDBid:JVNDB-2008-002560

Trust: 0.8

db:CNNVDid:CNNVD-200803-024

Trust: 0.7

db:XFid:0

Trust: 0.6

db:MILW0RMid:4744

Trust: 0.6

db:BIDid:85230

Trust: 0.4

db:VULHUBid:VHN-30064

Trust: 0.1

sources: VULHUB: VHN-30064 // BID: 85230 // JVNDB: JVNDB-2008-002560 // CNNVD: CNNVD-200803-024 // NVD: CVE-2007-6702

REFERENCES

url:http://osvdb.org/43168

Trust: 1.7

url:https://www.exploit-db.com/exploits/4744

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/39149

Trust: 1.1

url:http://www.milw0rm.com/exploits/4744

Trust: 0.9

url:http://xforce.iss.net/xforce/xfdb/39149

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-6702

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-6702

Trust: 0.8

sources: VULHUB: VHN-30064 // BID: 85230 // JVNDB: JVNDB-2008-002560 // CNNVD: CNNVD-200803-024 // NVD: CVE-2007-6702

CREDITS

Unknown

Trust: 0.3

sources: BID: 85230

SOURCES

db:VULHUBid:VHN-30064
db:BIDid:85230
db:JVNDBid:JVNDB-2008-002560
db:CNNVDid:CNNVD-200803-024
db:NVDid:CVE-2007-6702

LAST UPDATE DATE

2025-04-10T22:42:42.148000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-30064date:2017-09-29T00:00:00
db:BIDid:85230date:2008-03-04T00:00:00
db:JVNDBid:JVNDB-2008-002560date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200803-024date:2008-03-04T00:00:00
db:NVDid:CVE-2007-6702date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-30064date:2008-03-04T00:00:00
db:BIDid:85230date:2008-03-04T00:00:00
db:JVNDBid:JVNDB-2008-002560date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200803-024date:2008-03-04T00:00:00
db:NVDid:CVE-2007-6702date:2008-03-04T19:44:00