PT-2016-4851 · NetGear · Netgear Management System Nms300

Pedro Ribeiro

·

Publicado

2016-02-13

·

Atualizado

2018-10-09

·

CVE-2016-1525

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NETGEAR Management System NMS300 versions 1.5.0.11 and earlier
Description A directory traversal issue exists in the data/config/image.do endpoint, allowing remote authenticated users to read arbitrary files by using a .. (dot dot) in the realName parameter.
Recommendations For versions 1.5.0.11 and earlier, consider restricting access to the data/config/image.do endpoint until a fix is available, and avoid using the realName parameter with untrusted input.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-1525

Produtos afetados

Netgear Management System Nms300