vendor:
InfraPower PPS-02-S
by:
Gjoko 'LiquidWorm' Krstic
7,5
CVSS
HIGH
Local File Disclosure
22
CWE
Product Name: InfraPower PPS-02-S
Affected Version From: Q213V1 (Firmware: V2395S)
Affected Version To: Q216V3 (Firmware: IPD-02-FW-v03)
Patch Exists: YES
Related CWE: N/A
CPE: h:austin_hughes_electronics_ltd:infrapower_pps-02-s
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux 2.6.28 (armv5tel), lighttpd/1.4.30-devel-1321, PHP/5.3.9, SQLite/3.7.10
2016
InfraPower PPS-02-S Q213V1 Local File Disclosure Vulnerability
InfraPower suffers from a file disclosure vulnerability when input passed thru the 'file' parameter to 'ListFile.php' script is not properly verified before being used to read files. This can be exploited to disclose contents of files from local resources.
Mitigation:
Ensure that input passed thru the 'file' parameter to 'ListFile.php' script is properly verified before being used to read files.