.. / CVE-2010-2307

Exploit for Motorola SBV6120E SURFboard Digital Voice Modem SBV6X2X-1.0.0.5-SCM - Directory Traversal (CVE-2010-2307)

Description:

Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) “//” (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request.

Nuclei Template

View the template here CVE-2010-2307.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2010/CVE-2010-2307.yaml
Copy

References:

http://www.exploit-db.com/exploits/12865
https://exchange.xforce.ibmcloud.com/vulnerabilities/59113
https://github.com/ARPSyndicate/kenzer-templates
https://www.exploit-db.com/exploits/12865
https://nvd.nist.gov/vuln/detail/CVE-2010-2307