vendor:
Hanbanggaoke Webcams
by:
An independent security researcher
7,5
CVSS
HIGH
Arbitrary Password Change
20
CWE
Product Name: Hanbanggaoke Webcams
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: CVE-2017-14335
CPE: a:hanbanggaoke:webcams
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Arbitrary Password Change Vulnerability in Hanbanggaoke Webcams
User controlled input is not sufficiently sanitized, by sending a PUT request to /ISAPI/Security/users/1 HTTP/1.1 an attacker can change the admin password.
Mitigation:
At this time there is no solution or workaround for this vulnerability.