PT-2013-4471 · Airlive · Airlive Wl2600Cam

Eliezer Varadé Lopez

+2

·

Published

2013-10-04

·

Updated

2013-10-07

·

CVE-2013-3541

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions AirLive WL2600CAM (affected versions not specified)
Description A directory traversal issue exists in the cgi-bin/admin/fileread endpoint, allowing remote attackers to read arbitrary files by including a .. (dot dot) in the READ.filePath parameter.
Recommendations For AirLive WL2600CAM, restrict access to the cgi-bin/admin/fileread endpoint until a fix is available. As a temporary workaround, consider disabling the use of the READ.filePath parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3541

Affected Products

Airlive Wl2600Cam