vendor:
WH-H4
by:
LiquidWorm
3.3
CVSS
MEDIUM
Stream Disclosure
200
CWE
Product Name: WH-H4
Affected Version From: WH-H4 1.03R
Affected Version To: 2.0.0.P
Patch Exists: NO
Related CWE: N/A
CPE: h:iseeq:wh-h4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Boa/0.94.13, PHP/7.0.22, DVR Web Server
2019
iSeeQ Hybrid DVR WH-H4 2.0.0.P – (get_jpeg) Stream Disclosure
The DVR suffers from an unauthenticated and unauthorized live stream disclosure when get_jpeg script is called.
Mitigation:
Ensure that the get_jpeg script is not accessible to unauthorized users.