Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-0883. PoCs published by Sebastian Wolfgarten.
AI-analyzed exploit summary The exploit demonstrates an arbitrary file disclosure vulnerability in IP3 NetAccess devices (firmware < 4.1.9.6) via improper input validation in the 'getfile.cgi' script, allowing unauthenticated remote attackers to read sensitive files like /etc/shadow.
Description
Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
Exploits (1)
The exploit demonstrates an arbitrary file disclosure vulnerability in IP3 NetAccess devices (firmware < 4.1.9.6) via improper input validation in the 'getfile.cgi' script, allowing unauthenticated remote attackers to read sensitive files like /etc/shadow.