FLIR Systems FLIR AX8 Thermal Camera 1.32.16 Arbitrary File Disclosure

Discussion in 'News Aggregator' started by Packet Storm, 16 Oct 2018.

  1. Packet Storm

    Packet Storm Guest

    The FLIR AX8 thermal sensor camera version 1.32.16 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed via the 'file' parameter in download.php is not properly verified before being used to download config files. This can be exploited to disclose the contents of arbitrary files via absolute path.

    Continue reading...
     

Share This Page

Loading...