5

CVE-2010-2466

Exploit
The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloading of database backups, which allows remote attackers to obtain sensitive information via requests for full_*.dar files with predictable filenames.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
S2sysNetbox Version2.5
S2sysNetbox Version3.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.92% 0.772
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://blip.tv/file/3414004
Exploit
http://www.slideshare.net/shawn_merdinger/we-dont-need-no-stinkin-badges-hacking-electronic-door-access-controllersquot-shawn-merdinger-carolinacon
Exploit
http://www.darkreading.com/blog/archives/2010/04/attacking_door.html
http://www.securityinfowatch.com/Executives+Columns+%2526+Features/1316527?pageNum=2
http://www.kb.cert.org/vuls/id/228737
US Government Resource
https://exchange.xforce.ibmcloud.com/vulnerabilities/59826