LOW
img/main.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote authenticated users to read arbitrary files in img/ via a filename in the next_file parameter, as demonstrated by reading .htpasswd to obtain the admin password, a different vulnerability than CVE-2004-2507
Published May 6, 2009
3.5
LOWCVSS 2.0
EPSS 0.92%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.