vendor:
RPi_Cam_Web_Interface
by:
Alexander Korznikov
7,5
CVSS
HIGH
Local File Read and Blind Command Injection
94
CWE
Product Name: RPi_Cam_Web_Interface
Affected Version From: <= v6.3.14
Affected Version To: <= v6.3.14
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2017
RPi Cam Control <= v6.3.14 (RCE) Multiple Vulnerabilities - preview.php
RPi Cam Control <= v6.3.14 is vulnerable to Local File Read and Blind Command Injection. Local File Read can be done by sending a POST request to the preview.php page with the download1 parameter set to the path of the file to be read. Blind Command Injection can be done by sending a POST request to the preview.php page with the convertCmd parameter set to the command to be executed. Blind Command Injection can be used with Local File Read to properly get the output of injected command.
Mitigation:
Upgrade to the latest version of RPi Cam Control.