[prev in list] [next in list] [prev in thread] [next in thread] 

List:       bugtraq
Subject:    Directory listing on B-FOCuS Wireless 802.11b/g ADSL2+ Router by "ECI Telecom LTD"
From:       "LegendaryZion" <moskito () smile ! net ! il>
Date:       2006-10-31 16:27:21
Message-ID: 000301c6fd1d$0ad46b50$6502a8c0 () zionsecutiy
[Download RAW message or body]


·= Security Advisory =·

Issue: B-FOCuS Wireless 802.11b/g ADSL2+ Router by "ECI Telecom LTD"
Discovered Date: 02/10/2006
Author: Tal Argoni, LegendaryZion. [talargoni at gmail.com]
Product Vendor: http://www.inoviatele.com/

Details:

B-FOCuS Wireless Router is prone to a directory listing Vulnerability.
The vulnerability exists in Web-Based Management , caused by the lack of 
poor configuration.

Exploitation URL:

http://target/html/defs/


Successful exploitation allow viewing the router files and configuration 
files.

Proof Of Concept:

http://target/html/defs/

Thanks,
Tal Argoni, CEH
www.zion-security.com 

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic