Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-1334

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2008-1334
Last Modified 11 Oct 2008 01:51:39
Published 13 Mar 2008 02:44:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-1334

Summary

cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP telephone calls, by placing a character at the end of the PATH_INFO, as demonstrated by (1) %5C (encoded backslash), (2) '%' (percent), and (3) '~' (tilde). NOTE: the '/' (slash) vector is already covered by CVE-2007-5383.

Vulnerable Systems


References

XF - bthomehub-cgib-auth-bypass(41271)

BUGTRAQ - 20080301 The Router Hacking Challenge is Over!

MISC - http://www.gnucitizen.org/projects/router-hacking-challenge/

MISC - http://www.gnucitizen.org/blog/holes-in-embedded-devices-authentication-bypass-pt-1/


Last Updated: 27 May 2016 10:47:07