vendor:
GV-SNVR0811
by:
Berk Dusunur
4.3
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: GV-SNVR0811
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: h:geovision:gv-snvr0811
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Parrot OS
2018
GeoVision GV-SNVR0811 Directory Traversal
A directory traversal vulnerability exists in GeoVision GV-SNVR0811, which allows an attacker to read arbitrary files on the system. This is achieved by sending a specially crafted GET request containing directory traversal sequences such as '../../../../../../../../../../../../etc/passwd' to the target.
Mitigation:
Ensure that user input is validated and sanitized before being used in file operations.