PT-2018-6542 · Yawcam · Yawcam

David Panter

·

Published

2018-01-10

·

Updated

2018-02-02

·

CVE-2017-17662

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Yawcam versions 0.2.6 through 0.6.0
Description: The issue allows attackers to read arbitrary files through a sequence of directory traversal characters. This can be achieved by using a pattern composed of one or more of either or .., such as '../' or '..../' sequences. For files with no extension, a single dot needs to be appended to the request to prevent the HTTP server from altering it.
Recommendations: For Yawcam versions 0.2.6 through 0.6.0, consider restricting access to the HTTP server until a patch is available. As a temporary workaround, avoid using the HTTP server for sensitive file access.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17662

Affected Products

Yawcam