Lucene search

K
cve[email protected]CVE-2004-2749
HistoryNov 14, 2007 - 2:00 a.m.

CVE-2004-2749

2007-11-1402:00:00
CWE-22
web.nvd.nist.gov
27
cve-2004-2749
directory traversal
2wire gateway
remote attack

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7.2 High

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.2%

Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files via a … (dot dot) in the return parameter. NOTE: this issue was reported as XSS, but this might be a terminology error.

Affected configurations

NVD
Node
2wirehomeportalMatch100s
OR
2wirehomeportalMatch100w
OR
2wirehomeportalMatch1000
OR
2wirehomeportalMatch1000s
OR
2wirehomeportalMatch1000sw
OR
2wirehomeportalMatch1000w
OR
2wirehomeportalMatch1500w

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7.2 High

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.2%

Related for CVE-2004-2749