PT-2018-17927 · Twonky · Twonky Server

Sven Fassbender

·

Publicado

2018-03-30

·

Atualizado

2018-04-20

·

CVE-2018-7171

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Twonky Server versions 7.0.11 through 8.5
Description The issue allows remote attackers to share the contents of arbitrary directories. This is achieved by using a .. (dot dot) in the contentbase parameter to the "rpc/set all" endpoint.
Recommendations For Twonky Server versions 7.0.11 through 8.5, consider restricting access to the contentbase parameter in the "rpc/set all" endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the contentbase parameter with untrusted input until a patch is available.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7171

Produtos afetados

Twonky Server