vendor:
MiniDVBLinux
by:
LiquidWorm
7.5
CVSS
HIGH
Arbitrary File Read
22
CWE
Product Name: MiniDVBLinux
Affected Version From: <=5.4
Affected Version To: <=5.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: armhf, armhf-rpi2, GNU/Linux 4.19.127.203 (armv7l), VideoDiskRecorder 2.4.6
2022
MiniDVBLinux 5.4 – Arbitrary File Read
The distribution suffers from an arbitrary file disclosure vulnerability. Using the 'file' GET parameter attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.
Mitigation:
Ensure that the application is not vulnerable to arbitrary file disclosure.