CVE-2006-5536
D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 - Directory Traversal via getpage Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5536. PoCs published by jose.palanco.
AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in D-Link DSL-G624T devices by manipulating the 'getpage' parameter to access sensitive files like '/etc/passwd' and '/etc/config.xml'. The attack is performed via unauthenticated HTTP requests.
Description
Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to read arbitrary files via a .. (dot dot) in the getpage parameter.
Exploits (1)
This exploit leverages a directory traversal vulnerability in D-Link DSL-G624T devices by manipulating the 'getpage' parameter to access sensitive files like '/etc/passwd' and '/etc/config.xml'. The attack is performed via unauthenticated HTTP requests.