Логотип exploitDog
bind:CVE-2019-25290
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-25290

Количество 2

Количество 2

nvd логотип

CVE-2019-25290

около 1 месяца назад

Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage functionality through the 'host' parameter. Attackers can exploit the onvif.cgi endpoint by specifying external domains to bypass firewalls and perform network enumeration through arbitrary HTTP requests.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jfj5-mxvh-9vgr

около 1 месяца назад

Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage functionality through the 'host' parameter. Attackers can exploit the onvif.cgi endpoint by specifying external domains to bypass firewalls and perform network enumeration through arbitrary HTTP requests.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-25290

Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage functionality through the 'host' parameter. Attackers can exploit the onvif.cgi endpoint by specifying external domains to bypass firewalls and perform network enumeration through arbitrary HTTP requests.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-jfj5-mxvh-9vgr

Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage functionality through the 'host' parameter. Attackers can exploit the onvif.cgi endpoint by specifying external domains to bypass firewalls and perform network enumeration through arbitrary HTTP requests.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу