[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99602

 
 

909

 
 

80170

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2007-4915

Date: (C)2007-09-17   (M)2017-10-04 


The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allows remote attackers to change the admin password stored in memory via a long username in an HTTP Basic Authentication request.

CVSS Score: 10.0Access Vector: NETWORK
Exploit Score: 10.0Access Complexity: LOW
Impact Score: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE





Reference:
http://www.securityfocus.com/archive/1/archive/1/479434/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/489009/100/0/threaded
BID-25676
SREASON-3151
EXPLOIT-DB-4542
http://www.gnucitizen.org/projects/router-hacking-challenge/
http://www.ikkisoft.com/stuff/SN-2007-02.txt
http://www.securenetwork.it/ricerca/advisory/download/SN-2007-02.txt

CWE    1
CWE-20

© 2013 SecPod Technologies