5
CVSSv2

CVE-2006-2901

Published: 07/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware 2.10na and previous versions allows remote malicious users to obtain sensitive system information via a request to an arbitrary .cfg file, which returns configuration information including passwords.

Vulnerable Product Search on Vulmon Subscribe to Product

d-link dwl-2100ap

Exploits

# ADVISORY/0206 - D-Link Wireless Access-Point (DWL-2100ap) # INTRUDERS TIGER TEAM SECURITY - SECURITY ADVISORY # wwwintruderscombr/ , wwwintrudersorgbr/ Making a HTTP request to the /cgi-bin/ directory, the Web server will return error 404 (Page not found) Making a HTTP request to the /cgi-bin/AnyFilehtm, the Web server will ...