A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4 and classified as problematic. Affected by this vulnerability is the function sub_1DA58 of the file mainfunction.cgi. The manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222259.
References
Link | Resource |
---|---|
https://github.com/xxy1126/Vuln/blob/main/Draytek/3.md | Exploit |
https://vuldb.com/?id.222259 | Third Party Advisory VDB Entry |
https://vuldb.com/?ctiid.222259 | Permissions Required Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2023-03-02 23:15
Updated : 2023-03-10 11:00
NVD link : CVE-2023-1163
Mitre link : CVE-2023-1163
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
draytek
- vigor_2960_firmware
- vigor_2960