VideoFlow Digital Video Protection DVP 10 Authenticated Directory Traversal

Discussion in 'News Aggregator' started by Packet Storm, 3 Apr 2018.

  1. Packet Storm

    Packet Storm Guest

    VideoFlow Digital Video Protection DVP 10 version 2.10 suffers from an authenticated arbitrary file disclosure vulnerability including no session expiration. Input passed via the 'ID' parameter in several Perl scripts is not properly verified before being used to download system files. This can be exploited to disclose the contents of arbitrary files via directory traversal attacks.

    Continue reading...
     

Share This Page

Loading...