CVE-2016-15038
NUUO NVRmini 2 deletefile.php path traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability, which was classified as critical, was found in NUUO NVRmini 2 up to 3.0.8. Affected is an unknown function of the file /deletefile.php. The manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258780.
Una vulnerabilidad fue encontrada en NUUO NVRmini 2 hasta 3.0.8 y clasificada como crítica. Una función desconocida del archivo /deletefile.php es afectada por esta vulnerabilidad. La manipulación del argumento filnename conduce a un path traversal. Es posible lanzar el ataque de forma remota. El exploit ha sido divulgado al público y puede utilizarse. El identificador de esta vulnerabilidad es VDB-258780.
Es wurde eine Schwachstelle in NUUO NVRmini 2 bis 3.0.8 gefunden. Sie wurde als kritisch eingestuft. Es betrifft eine unbekannte Funktion der Datei /deletefile.php. Mittels dem Manipulieren des Arguments filename mit unbekannten Daten kann eine path traversal-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-03-30 CVE Reserved
- 2024-04-01 CVE Published
- 2024-08-27 CVE Updated
- 2024-08-27 First Exploit
- 2024-10-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.258780 | Technical Description |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/40214 | 2024-08-27 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
NUUO Search vendor "NUUO" | NVRmini 2 Search vendor "NUUO" for product "NVRmini 2" | 3.0.0 Search vendor "NUUO" for product "NVRmini 2" and version "3.0.0" | en |
Affected
| ||||||
NUUO Search vendor "NUUO" | NVRmini 2 Search vendor "NUUO" for product "NVRmini 2" | 3.0.1 Search vendor "NUUO" for product "NVRmini 2" and version "3.0.1" | en |
Affected
| ||||||
NUUO Search vendor "NUUO" | NVRmini 2 Search vendor "NUUO" for product "NVRmini 2" | 3.0.2 Search vendor "NUUO" for product "NVRmini 2" and version "3.0.2" | en |
Affected
| ||||||
NUUO Search vendor "NUUO" | NVRmini 2 Search vendor "NUUO" for product "NVRmini 2" | 3.0.3 Search vendor "NUUO" for product "NVRmini 2" and version "3.0.3" | en |
Affected
| ||||||
NUUO Search vendor "NUUO" | NVRmini 2 Search vendor "NUUO" for product "NVRmini 2" | 3.0.4 Search vendor "NUUO" for product "NVRmini 2" and version "3.0.4" | en |
Affected
| ||||||
NUUO Search vendor "NUUO" | NVRmini 2 Search vendor "NUUO" for product "NVRmini 2" | 3.0.5 Search vendor "NUUO" for product "NVRmini 2" and version "3.0.5" | en |
Affected
| ||||||
NUUO Search vendor "NUUO" | NVRmini 2 Search vendor "NUUO" for product "NVRmini 2" | 3.0.6 Search vendor "NUUO" for product "NVRmini 2" and version "3.0.6" | en |
Affected
| ||||||
NUUO Search vendor "NUUO" | NVRmini 2 Search vendor "NUUO" for product "NVRmini 2" | 3.0.7 Search vendor "NUUO" for product "NVRmini 2" and version "3.0.7" | en |
Affected
| ||||||
NUUO Search vendor "NUUO" | NVRmini 2 Search vendor "NUUO" for product "NVRmini 2" | 3.0.8 Search vendor "NUUO" for product "NVRmini 2" and version "3.0.8" | en |
Affected
|