vendor:
NUUO NVRmini 2
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Local File Disclosure
CWE
Product Name: NUUO NVRmini 2
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: GNU/Linux
2016
NUUO Local File Disclosure Vulnerability
NUUO NVRmini, NVRmini2, Crystal and NVRSolo suffers from a file disclosure vulnerability when input passed thru the 'css' parameter to 'css_parser.php' script is not properly verified before being used to include files. This can be exploited to disclose contents of files from local resources.