9
CVSSv2

CVE-2007-3266

Published: 19/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 9 | Impact Score: 8.5 | Exploitability Score: 10
VMScore: 905
Vector: AV:N/AC:L/Au:N/C:C/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote malicious users to include and execute arbitrary local files a .. (dot dot) in the outconfig parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ifnet webif.cgi

Exploits

source: wwwsecurityfocuscom/bid/24516/info WebIf is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input Exploiting this issue may allow an unauthorized user to view files and execute local scripts wwwexamplecom/webif/webifcgi?cmd=query&config=conf_2000/configtxt&out ...