PT-2013-4471 · Airlive · Airlive Wl2600Cam
Eliezer Varadé Lopez
+2
·
Published
2013-10-04
·
Updated
2013-10-07
·
CVE-2013-3541
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AirLive WL2600CAM (affected versions not specified)
Description
A directory traversal issue exists in the cgi-bin/admin/fileread endpoint, allowing remote attackers to read arbitrary files by including a .. (dot dot) in the
READ.filePath parameter.Recommendations
For AirLive WL2600CAM, restrict access to the cgi-bin/admin/fileread endpoint until a fix is available. As a temporary workaround, consider disabling the use of the
READ.filePath parameter in the affected endpoint to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Airlive Wl2600Cam