Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2vjf-4p28-j7qj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.

EPSS

Процентиль: 96%
0.21375
Средний

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.

EPSS

Процентиль: 96%
0.21375
Средний

Дефекты

CWE-22