CVE-2007-6638

March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz.

MILW0RM: http://www.milw0rm.com/exploits/4797
MISC: http://www.milw0rm.com/papers/190
MISC: http://www.sybsecurity.com/advisors/SYBSEC-ADV14-March_Networks_DVR_3204_Logfile_Information_Disclosure
MISC: http://www.sybsecurity.com/pages/advisors/static/dvr3204_exp.txt
MISC: http://www.sybsecurity.com/resources/static/An_Insecurity_Overview_of_the_March_Networks_DVR-CCTV_3204.pdf
BID: http://www.securityfocus.com/bid/27054
OSVDB: http://osvdb.org/39726
SECUNIA: http://secunia.com/advisories/28211
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6638

7 years
228 countries
153k users
1061k calculations
Logo secutek.cz
Logo www.elsec.cz
Logo reolink.com
Logo www.a1securitycameras.com
Logo www.power-shop.gr
Logo sectech.co.nz