vendor:
SP2
by:
shinnai
7.5
CVSS
HIGH
Insecure Method
601
CWE
Product Name: SP2
Affected Version From: NVR SP2 2.0
Affected Version To: NVR SP2 2.0
Patch Exists: NO
Related CWE: Not available
CPE: a:nvr:sp2:2.0
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
NVR SP2 2.0 nvUtility.Utility.1 (nvUtility.dll v. 1.0.14.0) ‘DeleteXMLFile()’ Insecure Method
This exploit targets the 'DeleteXMLFile()' method in the NVR SP2 2.0 nvUtility.Utility.1 control. It allows an attacker to delete arbitrary files on the system. All software that uses this control is vulnerable to this exploit.
Mitigation:
The vendor should update the control to fix the insecure method and ensure that it is safe for use in untrusted environments.