vendor:
Dreambox
by:
ShellVision
7.5
CVSS
HIGH
Arbitrary File Download
22
CWE
Product Name: Dreambox
Affected Version From: dm800 <= 1.6rc3
Affected Version To: dm800 <= 1.6rc3
Patch Exists: NO
Related CWE: N/A
CPE: o:dream_multimedia:dreambox_dm800
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2011
DreamBox DM800 Arbitrary File Download Vulnerability
Dreambox suffers from a file download vulnerability thru directory traversal with appending the '/' character in the HTTP GET method of the affected host address. The attacker can get to sensitive information like paid channel keys, usernames, passwords, config and plug-ins info, etc. By default, web application is running by root, so catch shadow is very easy.
Mitigation:
Ensure that the web application is not running as root and restrict access to sensitive files.