Cybertrion Systems

[2/5] March Networks 3204 DVR Logfile Information Disclosure

December 28th, 2007 by
[2/5] March Networks 3204 DVR Logfile Information Disclosure

:Alex Hernandez has reported a security issue in March Networks 3204 DVR, which can be exploited by malicious people to disclose sensitive information.The problem is that it is possible to download the logfiles, which contain certain sensitive information (e.g. usernames and passwords), by accessing a specific URL.The security issue is reported in 3204 DVR. Other versions may also be affected.Solution:The vendor has reportedly released a fix.Provided and/or discovered by:Alex Hernandez, SYB SecurityOriginal Advisory:http://www.sybsecurity.com/advisors/S…R_3204_Logfile_Information_Disclosure

Original post by Pankaj

[2/5] March Networks 3204 DVR Logfile Information Disclosure

Related Articles:
  • [3/5] Fedora update for vdccm
  • [2/5] BlueCat Networks Adonis Heartbeat Denial of Service
  • [2/5] Hal Networks Products Cross-Site Scripting Vulnerabilities
  • [3/5] HTTP File Server Multiple Vulnerabilities
  • [3/5] ALAXALA Networks AX Series BGP UPDATE Message Processing Denial of Service


  • Posted in Advisories - Exploits | | [2/5] March Networks 3204 DVR Logfile Information Disclosure

    << [3/5] FAQMasterFlexPlus Cross-Site Scripting and SQL Injection | [3/5] RunCms Multiple Vulnerabilities >>