information-paradox.net
http://www.information-paradox.net/2017/12/conarc-ichannel-unauthenticated.html CVE-2017-17759
CRITICAL
Conarc iChannel - Improper Access Restrictions
Record summary
CVE-2017-17759 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request (which reaches an older version of a West Wind Web Connection HTTP service).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBConarc iChannel - Improper Access RestrictionsExploitDB exploitby Information ParadoxNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-17759 43377exploit
https://www.exploit-db.com/exploits/43377