Описание
A vulnerability was identified in D-Link DCS-700L 1.03.09. The affected element is the function uploadmusic of the file /setUploadMusic of the component Music File Upload Service. The manipulation of the argument UploadMusic leads to path traversal. The attack can only be initiated within the local network. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
Ссылки
- ExploitThird Party Advisory
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Product
Уязвимые конфигурации
Одновременно
EPSS
2.4 Low
CVSS3
5.5 Medium
CVSS3
2.2 Low
CVSS2
Дефекты
Связанные уязвимости
A vulnerability was identified in D-Link DCS-700L 1.03.09. The affected element is the function uploadmusic of the file /setUploadMusic of the component Music File Upload Service. The manipulation of the argument UploadMusic leads to path traversal. The attack can only be initiated within the local network. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
Уязвимость службы Music File Upload Service микропрограммного обеспечения IP-камер D-Link DCS-700L, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
2.4 Low
CVSS3
5.5 Medium
CVSS3
2.2 Low
CVSS2