Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g24h-8xr2-34q6

Опубликовано: 09 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 5.3

Описание

MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attackers to generate live stream snapshots through the Simple VDR Protocol. Attackers can request /tpl/tv_action.sh to create and retrieve a live TV screenshot stored in /var/www/images/tv.jpg without authentication.

MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attackers to generate live stream snapshots through the Simple VDR Protocol. Attackers can request /tpl/tv_action.sh to create and retrieve a live TV screenshot stored in /var/www/images/tv.jpg without authentication.

EPSS

Процентиль: 69%
0.00597
Низкий

8.7 High

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 5.3
nvd
2 месяца назад

MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attackers to generate live stream snapshots through the Simple VDR Protocol. Attackers can request /tpl/tv_action.sh to create and retrieve a live TV screenshot stored in /var/www/images/tv.jpg without authentication.

EPSS

Процентиль: 69%
0.00597
Низкий

8.7 High

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-306