Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request (which reaches an older version of a West Wind Web Connection HTTP service).
Link | Tags |
---|---|
http://www.information-paradox.net/2017/12/conarc-ichannel-unauthenticated.html | issue tracking third party advisory |
https://www.exploit-db.com/exploits/43377/ | issue tracking exploit vdb entry third party advisory |