PT-2013-4746 · Savysoda · Savysoda Wifi Hd Free

Published

2013-11-26

·

Updated

2017-08-29

·

CVE-2013-3923

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SavySoda WiFi HD Free versions prior to 7.0
Description A directory traversal issue allows remote attackers to read arbitrary files by including a ..%2f (encoded dot dot slash) in a GET request to specific API endpoints, such as "/api/v1/files". This could potentially expose sensitive information.
Recommendations For versions prior to 7.0, update to version 7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3923

Affected Products

Savysoda Wifi Hd Free