Vulnerabilities > CVE-2006-5536 - Information Disclosure vulnerability in D-Link Dsl-G624T Firmware3.00B01T01.Yac.20060616
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to read arbitrary files via a .. (dot dot) in the getpage parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Hardware | 1 |
Exploit-Db
description | D-Link DSL-G624T Information Disclosure Vulnerability. CVE-2006-5536. Remote exploit for hardware platform |
id | EDB-ID:28847 |
last seen | 2016-02-03 |
modified | 2006-10-23 |
published | 2006-10-23 |
reporter | jose.palanco |
source | https://www.exploit-db.com/download/28847/ |
title | D-Link DSL-G624T Information Disclosure Vulnerability |
References
- http://secunia.com/advisories/22524
- http://securityreason.com/securityalert/1781
- http://www.eazel.es/advisory005-D-Link-DSL-G624T-directoy-transversal-xss-cross-site-scripting-directory-listing-vulnerabilities.html
- http://www.securityfocus.com/archive/1/449486/100/0/threaded
- http://www.securityfocus.com/bid/20689
- http://www.vupen.com/english/advisories/2006/4191