PT-2013-4471 · Airlive · Airlive Wl2600Cam

Eliezer Varadé Lopez

+2

·

Publicado

2013-10-04

·

Atualizado

2013-10-07

·

CVE-2013-3541

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions AirLive WL2600CAM (affected versions not specified)
Description A directory traversal issue exists in the cgi-bin/admin/fileread endpoint, allowing remote attackers to read arbitrary files by including a .. (dot dot) in the READ.filePath parameter.
Recommendations For AirLive WL2600CAM, restrict access to the cgi-bin/admin/fileread endpoint until a fix is available. As a temporary workaround, consider disabling the use of the READ.filePath parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3541

Produtos afetados

Airlive Wl2600Cam