CVE-2007-6638
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 12%
from disclosure to weapon3742 days
Published on NVDJan 4
1st PoC+3742d
exploitation probability
12%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz.
Affected products
n/a · n/apublic PoCs found — 2
githubgithub.com/alt3kx/CVE-2007-6638★ 0cve_referencewww.exploit-db.com/exploits/4797unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/39726http://secunia.com/advisories/28211https://www.exploit-db.com/exploits/4797http://www.milw0rm.com/papers/190http://www.securityfocus.com/bid/27054http://www.sybsecurity.com/advisors/SYBSEC-ADV14-March_Networks_DVR_3204_Logfile_Information_Disclosurehttp://www.sybsecurity.com/pages/advisors/static/dvr3204_exp.txthttp://www.sybsecurity.com/resources/static/An_Insecurity_Overview_of_the_March_Networks_DVR-CCTV_3204.pdf