/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T17:18:02.190Z
Reserved: 2017-06-23T00:00:00
Link: CVE-2017-9833
No data.
Status : Deferred
Published: 2017-06-24T02:29:00.207
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-9833
No data.
OpenCVE Enrichment
No data.
Weaknesses