CVE-2016-10106
03.01.2017, 06:59
Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thispage parameter, as demonstrated by reading the /etc/shadow file.
Vendor | Product | Version |
---|---|---|
netgear | fvs336gv3_firmware | 𝑥 ≤ 4.3-3.6 |
netgear | srx5308_firmware | 𝑥 ≤ 4.3-3.6 |
netgear | fvs318gv2_firmware | 𝑥 ≤ 4.3-3.6 |
netgear | fvs318n_firmware | 𝑥 ≤ 4.3-3.6 |
𝑥
= Vulnerable software versions
References