Metrics
Affected Vendors & Products
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 06 Sep 2024 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Za-internet
Za-internet c-mor Video Surveillance |
|
CPEs | cpe:2.3:a:za-internet:c-mor_video_surveillance:5.2401:*:*:*:*:*:*:* | |
Vendors & Products |
Za-internet
Za-internet c-mor Video Surveillance |
|
References |
|
|
Metrics |
ssvc
|
Fri, 06 Sep 2024 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | ||
Vendors & Products |
Za-internet
Za-internet c-mor Video Surveillance |
|
References |
| |
Metrics |
ssvc
|
Thu, 05 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Za-internet
Za-internet c-mor Video Surveillance |
|
Weaknesses | CWE-434 | |
CPEs | cpe:2.3:a:za-internet:c-mor_video_surveillance:5.2401:*:*:*:*:*:*:* | |
Vendors & Products |
Za-internet
Za-internet c-mor Video Surveillance |
|
Metrics |
cvssV3_1
|
Thu, 05 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous files, for instance PHP code, to the C-MOR system. By analyzing the C-MOR web interface, it was found out that the upload functionality for backup files allows an authenticated user to upload arbitrary files. The only condition is that the filename contains a .cbkf string. Therefore, webshell.cbkf.php is considered a valid file name for the C-MOR web application. Uploaded files are stored within the directory "/srv/www/backups" on the C-MOR system, and can thus be accessed via the URL https://<HOST>/backup/upload_<FILENAME>. Due to broken access control, low-privileged authenticated users can also use this file upload functionality. | |
References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-05T00:00:00
Updated: 2024-09-06T06:03:35.338Z
Reserved: 2024-08-22T00:00:00
Link: CVE-2024-45171
Updated: 2024-09-05T15:55:22.425Z
Status : Awaiting Analysis
Published: 2024-09-05T16:15:08.477
Modified: 2024-11-21T09:37:24.030
Link: CVE-2024-45171
No data.