CVE-2013-6023

Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote attackers to read arbitrary files via .. (dot dot) in the URI.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:tvt:dvr:td-2308ss-b:-:*:*:*:*:*:*
OR cpe:2.3:o:tvt:dvr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.1.6.p-1.0.2.1-03:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.1.7.b-1.0.2.1-00:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.1.43.b:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.1.43.p:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.1.75.b-1.0.2.1-00:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.1.81.b-1.0.2.1-00:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.1.83.b-1.0.2.1-00:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.1.83.p-1.0.4.2-03:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.1.87.p-1.0.4.2-17:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.1.91.p-1.0.2.1-03:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.1.92.p-1.0.2.1-00:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.1.93.b-1.0.2.1-17:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.2.0.b-1.0.2.1-17:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.2.0.p-1.0.2.1-03:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.2.0.p-1.0.2.1-17:*:*:*:*:*:*:*
cpe:2.3:o:tvt:dvr_firmware:3.2.0.p-1.0.6.0.32-00:*:*:*:*:*:*:*

History

21 Nov 2024, 01:58

Type Values Removed Values Added
References () http://alguienenlafisi.blogspot.com/2013/10/dvr-tvt-directory-traversal.html - () http://alguienenlafisi.blogspot.com/2013/10/dvr-tvt-directory-traversal.html -
References () http://www.exploit-db.com/exploits/29959 - Exploit () http://www.exploit-db.com/exploits/29959 - Exploit
References () http://www.kb.cert.org/vuls/id/785838 - US Government Resource () http://www.kb.cert.org/vuls/id/785838 - US Government Resource
References () http://www.securityfocus.com/bid/63360 - Exploit () http://www.securityfocus.com/bid/63360 - Exploit

Information

Published : 2013-11-02 21:55

Updated : 2024-11-21 01:58


NVD link : CVE-2013-6023

Mitre link : CVE-2013-6023

CVE.ORG link : CVE-2013-6023


JSON object : View

Products Affected

tvt

  • dvr_firmware
  • dvr
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')