Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to read arbitrary files via a .. (dot dot) in the getpage parameter.
📦
dsl-g624t
Vendor: d-link
Actively Exploited
0
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
0
Remote Access
Total CVEs
9
Total Indexed
Avg. EPSS
5.35%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
5.0
CVSS
CVE-2006-5536
Exploit Found
Severity: MEDIUM
4.3
CVSS
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allow remote attackers to inject arbitrary web script or HTML via the (1) upnp:settings/state or (2) upnp:settings/connection parameters.
Severity: MEDIUM
5.0
CVSS
D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to list contents of the cgi-bin directory via unspecified vectors, probably a direct request.
Severity: MEDIUM