Описание
MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive system files through the 'file' GET parameter. Attackers can exploit the about page by supplying file paths to disclose arbitrary file contents on the affected device.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Product
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.4 (включая)
cpe:2.3:a:minidvblinux:minidvblinux:*:*:*:*:*:*:*:*
EPSS
Процентиль: 74%
0.00842
Низкий
7.5 High
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 7.5
github
около 2 месяцев назад
MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive system files through the 'file' GET parameter. Attackers can exploit the about page by supplying file paths to disclose arbitrary file contents on the affected device.
EPSS
Процентиль: 74%
0.00842
Низкий
7.5 High
CVSS3
Дефекты
CWE-22