Vulnerabilities > CVE-2006-2901 - Information Disclosure vulnerability in D-Link DWL-2100AP

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
d-link
exploit available

Summary

The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware 2.10na and earlier allows remote attackers to obtain sensitive system information via a request to an arbitrary .cfg file, which returns configuration information including passwords.

Vulnerable Configurations

Part Description Count
Hardware
D-Link
1

Exploit-Db

descriptionD-Link Access-Point <= 2.10na (DWL Series) Config Disclosure Vuln. CVE-2006-2901. Remote exploit for hardware platform
idEDB-ID:1889
last seen2016-01-31
modified2006-06-08
published2006-06-08
reporterINTRUDERS
sourcehttps://www.exploit-db.com/download/1889/
titleD-Link Access-Point <= 2.10na - DWL Series Config Disclosure Vuln