Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-8389

Опубликовано: 17 фев. 2019
Источник: nvd
CVSS3: 8.1
CVSS2: 4.8
EPSS Низкий

Описание

A file-read vulnerability was identified in the Wi-Fi transfer feature of Musicloud 1.6. By default, the application runs a transfer service on port 8080, accessible by everyone on the same Wi-Fi network. An attacker can send the POST parameters downfiles and cur-folder (with a crafted ../ payload) to the download.script endpoint. This will create a MusicPlayerArchive.zip archive that is publicly accessible and includes the content of any requested file (such as the /etc/passwd file).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:musicloud_project:musicloud:1.6:*:*:*:*:iphone_os:*:*

EPSS

Процентиль: 90%
0.05384
Низкий

8.1 High

CVSS3

4.8 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

A file-read vulnerability was identified in the Wi-Fi transfer feature of Musicloud 1.6. By default, the application runs a transfer service on port 8080, accessible by everyone on the same Wi-Fi network. An attacker can send the POST parameters downfiles and cur-folder (with a crafted ../ payload) to the download.script endpoint. This will create a MusicPlayerArchive.zip archive that is publicly accessible and includes the content of any requested file (such as the /etc/passwd file).

EPSS

Процентиль: 90%
0.05384
Низкий

8.1 High

CVSS3

4.8 Medium

CVSS2

Дефекты

CWE-22