CVE-2007-0357
fritzdsl 02.02.29 - Directory Traversal via URL-Encoded Dot Dot Backslash Sequences
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0357. PoCs published by DPR.
AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in the AVM Fritz!DSL IGD Control Service to retrieve arbitrary files with SYSTEM-level privileges. The PoC demonstrates the vulnerability by accessing the 'system.ini' file via a crafted URL.
Description
Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-encoded dot dot backslash) sequences in a URI requested from the AR7 webserver.
Exploits (1)
This exploit leverages a directory traversal vulnerability in the AVM Fritz!DSL IGD Control Service to retrieve arbitrary files with SYSTEM-level privileges. The PoC demonstrates the vulnerability by accessing the 'system.ini' file via a crafted URL.