Absolute path traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R24 and possibly 1.00R22 allows remote attackers to read arbitrary files via an absolute pathname in the this_file parameter. NOTE: traversal via a .. (dot dot) is probably also possible.
Advisories
Source ID Title
EUVD EUVD EUVD-2009-1555 Absolute path traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R24 and possibly 1.00R22 allows remote attackers to read arbitrary files via an absolute pathname in the this_file parameter. NOTE: traversal via a .. (dot dot) is probably also possible.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T05:20:34.000Z

Reserved: 2009-05-06T00:00:00

Link: CVE-2009-1559

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2009-05-06T16:30:00.657

Modified: 2025-04-09T00:30:58.490

Link: CVE-2009-1559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses