5

CVE-2010-2465

Exploit
The S2 Security NetBox 2.5, 3.3, and 4.0, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download node logs, photographs of persons, and backup files via unspecified HTTP requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
S2sysNetbox Version2.5
S2sysNetbox Version3.3
S2sysNetbox Version4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.46% 0.823
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://blip.tv/file/3414004
Exploit
http://www.slideshare.net/shawn_merdinger/we-dont-need-no-stinkin-badges-hacking-electronic-door-access-controllersquot-shawn-merdinger-carolinacon
Exploit
http://osvdb.org/65757
http://secunia.com/advisories/40374
http://www.darkreading.com/blog/archives/2010/04/attacking_door.html
http://www.kb.cert.org/vuls/id/251133
US Government Resource
http://www.kb.cert.org/vuls/id/MAPG-83TQL8
http://www.securityfocus.com/bid/41134
http://www.securityinfowatch.com/Executives+Columns+%2526+Features/1316527?pageNum=2