vendor:
Targa IP OCR-ANPR Camera
by:
LiquidWorm
7.5
CVSS
HIGH
Directory Traversal File Disclosure
22
CWE
Product Name: Targa IP OCR-ANPR Camera
Affected Version From: BLD201113005214
Affected Version To: BLD191021180140
Patch Exists: YES
Related CWE: CVE-2020-25862
CPE: h:selea:targa_ip_ocr-anpr_camera
Other Scripts:
N/A
Platforms Tested: Windows, Linux, Mac
2020
Selea Targa IP OCR-ANPR Camera Unauthenticated Directory Traversal File Disclosure
The ANPR camera suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' parameter in the 'get_file.cgi' script is not properly sanitized before being used to read files. This can be exploited to read arbitrary files from the underlying file system with the privileges of the web server process.
Mitigation:
Upgrade to the latest version of the firmware.