vendor:
Argus Surveillance DVR
by:
John Page (aka hyp3rlinx)
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Argus Surveillance DVR
Affected Version From: 4.0.0.0
Affected Version To: 4.0.0.0
Patch Exists: NO
Related CWE: N/A
CPE: a:argus_surveillance:argus_surveillance_dvr
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Exploit: Argus Surveillance DVR 4.0.0.0 – Directory Traversal
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.
Mitigation:
Ensure that the web application is properly configured to prevent directory traversal attacks.