5
CVSSv2

CVE-2010-2307

Published: 16/06/2010 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote malicious users to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request.

Vulnerable Product Search on Vulmon Subscribe to Product

motorola surfboard sbv6120e sbv6x2x-1.0.0.5-scm-02-shpc

Exploits

# Exploit Title: Motorola SURFBoard Cable Modem Directory Traversal # Date: 20100603 # Author: S2 Crew [Hungary] # Software Link: - # Version: Model name: SBV6120E, Firmware Name: SBV6X2X-1005-SCM-02-SHPC # Tested on: ^ # CVE: - # Code : The following urls get back the /etc/passwd file from the modem: [IP]///etc/passwd <[ip] ...