vendor:
Nano NXT
by:
Gjoko 'LiquidWorm' Krstic
5,9
CVSS
MEDIUM
Local File Disclosure
22
CWE
Product Name: Nano NXT
Affected Version From: NXT Firmware: 3.05.1193 (ICM: 3.5.1)
Affected Version To: NXT Firmware: 3.01.646 (ICM: 3.1.13)
Patch Exists: YES
Related CWE: CVE-2016-5356
CPE: a:eyelock:nano_nxt
Metasploit:
https://www.rapid7.com/db/vulnerabilities/wireshark-cve-2016-5356/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2016-5356/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-5356/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2016-5356/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2016-5356/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: GNU/Linux (armv7l), lighttpd/1.4.35, SQLite/3.8.7.2, PHP/5.6.6
2016
EyeLock nano NXT 3.5 Local File Disclosure Vulnerability
Nano NXT suffers from a file disclosure vulnerability when input passed thru the 'path' parameter to 'logdownload.php' script is not properly verified before being used to read files. This can be exploited to disclose contents of files from local resources.
Mitigation:
Input validation should be performed to ensure that untrusted data is not used to access local resources.