Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-2749. PoCs published by Rafel Ivgi The-Insider.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in the 2Wire HomePortal Series by manipulating the 'return' parameter in the 'wralogin' form to access files outside the server root, such as 'boot.ini'. The PoC uses a crafted URL to exploit the flaw.
Description
Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files via a .. (dot dot) in the return parameter. NOTE: this issue was reported as XSS, but this might be a terminology error.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in the 2Wire HomePortal Series by manipulating the 'return' parameter in the 'wralogin' form to access files outside the server root, such as 'boot.ini'. The PoC uses a crafted URL to exploit the flaw.