vendor:
HD-Network Real-time Monitoring System
by:
Momen Eldawakhly (Cyber Guy)
9.8
CVSS
CRITICAL
Local File Inclusion (LFI)
22
CWE
Product Name: HD-Network Real-time Monitoring System
Affected Version From: V2.0
Affected Version To: V2.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Nginx NVRDVRIPC Web Server
2021
HD-Network Real-time Monitoring System 2.0 – Local File Inclusion (LFI)
A Local File Inclusion (LFI) vulnerability exists in HD-Network Real-time Monitoring System 2.0. An attacker can send a specially crafted HTTP request to the vulnerable server to exploit this vulnerability and gain access to sensitive files on the server.
Mitigation:
To mitigate this vulnerability, the application should validate user input and restrict access to sensitive files.