Vulnerabilities > CVE-2007-0357 - Directory Traversal Information Disclosure vulnerability in Fritzdsl 02.02.29

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
fritzdsl
exploit available

Summary

Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-encoded dot dot backslash) sequences in a URI requested from the AR7 webserver.

Vulnerable Configurations

Part Description Count
Hardware
Fritzdsl
1

Exploit-Db

descriptionAVM Fritz!DSL IGD Control Service 2.2.29 Directory Traversal Information Disclosure Vulnerability. CVE-2007-0357. Remote exploit for windows platform
idEDB-ID:29490
last seen2016-02-03
modified2007-01-17
published2007-01-17
reporterDPR
sourcehttps://www.exploit-db.com/download/29490/
titleavm fritz!dsl igd control service 2.2.29 - Directory Traversal information disclosure Vulnerability