vendor:
Digital Video Protection DVP 10
by:
N/A
8.8
CVSS
HIGH
Authenticated arbitrary file disclosure vulnerability
22
CWE
Product Name: Digital Video Protection DVP 10
Affected Version From: 2.10
Affected Version To: 2.10
Patch Exists: YES
Related CWE: N/A
CPE: a:videoflow:digital_video_protection_dvp_10
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2018
VideoFlow Digital Video Protection DVP 10 Authenticated Directory Traversal
The application suffers from an authenticated arbitrary file disclosure vulnerability including no session expiration. Input passed via the 'ID' parameter in several Perl scripts is not properly verified before being used to download system files. This can be exploited to disclose the contents of arbitrary files via directory traversal attacks.
Mitigation:
Ensure that user input is properly sanitized and validated before being used to download system files.