A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.ini HTTP/1.1\n\n" - note the lack of "/" in the path field of the request) request that will disclose the configuration file with the login password.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-03-13T06:14:00
Updated: 2024-08-05T15:11:48.344Z
Reserved: 2017-01-31T00:00:00
Link: CVE-2017-5674
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2017-03-13T06:59:00.370
Modified: 2017-03-15T18:43:07.360
Link: CVE-2017-5674
Redhat
No data.