4
CVSSv2

CVE-2018-9010

Published: 25/03/2018 Updated: 09/09/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via the /cgi-bin/cgiServer.exx page parameter, aka absolute path traversal. In some cases, authentication can be achieved via the admin account with its default admin password.

Vulnerable Product Search on Vulmon Subscribe to Product

intelbras tip200_firmware 60.0.75.29

intelbras tip200lite_firmware 60.0.75.29

Exploits

# Exploit Title: [INTELBRAS TELEFONE IP TIP200/200 LITE Local File Include] # Google Dork: [] # Date: 16/03/2018 # Exploit Author: [Matheus Goncalves - anhax0r] # Vendor Homepage: [wwwfacebookcom/anhaxteam/] # Software Link: [] # Version: [6007529] (REQUIRED) # Tested on: [Debian] # CVE : [if applicable] #Remember that you need login ...