vendor:
Pelco VideoXpert
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Pelco VideoXpert
Affected Version From: 1.12.0105
Affected Version To: 2.0.41
Patch Exists: NO
Related CWE:
CPE: a:schneider_electric:pelco_videoxpert:2.0.41
Platforms Tested: Microsoft Windows 7 Professional SP1 (EN), Jetty(9.2.6.v20141205), MongoDB/3.2.10
2017
Schneider Electric Pelco VideoXpert Core Admin Portal Directory Traversal
The Pelco VideoXpert Core Admin Portal is vulnerable to directory traversal, allowing an unauthenticated attacker to view arbitrary files within the context of the web server.
Mitigation:
Upgrade to a version that is not affected, or apply the latest patch.