7.8
CVSSv2

CVE-2013-6023

Published: 02/11/2013 Updated: 31/03/2016
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and previous versions allows remote malicious users to read arbitrary files via .. (dot dot) in the URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tvt dvr td-2308ss-b

tvt dvr_firmware 3.1.43.b

tvt dvr_firmware 3.1.6.p-1.0.2.1-03

tvt dvr_firmware 3.1.91.p-1.0.2.1-03

tvt dvr_firmware 3.1.93.b-1.0.2.1-17

tvt dvr_firmware

tvt dvr_firmware 3.1.7.b-1.0.2.1-00

tvt dvr_firmware 3.1.81.b-1.0.2.1-00

tvt dvr_firmware 3.1.83.b-1.0.2.1-00

tvt dvr_firmware 3.1.83.p-1.0.4.2-03

tvt dvr_firmware 3.2.0.b-1.0.2.1-17

tvt dvr_firmware 3.2.0.p-1.0.2.1-03

tvt dvr_firmware 3.2.0.p-1.0.2.1-17

tvt dvr_firmware 3.2.0.p-1.0.6.0.32-00

tvt dvr_firmware 3.1.43.p

tvt dvr_firmware 3.1.75.b-1.0.2.1-00

tvt dvr_firmware 3.1.87.p-1.0.4.2-17

tvt dvr_firmware 3.1.92.p-1.0.2.1-00

Exploits

# Exploit Title: TVT TD-2308SS-B DVR directory traversal # Shodan Dork: "Cross Web Server" # Date: 01 Dec 2013 # Disclosure date: 10 Sep 2013 # Exploit Author: Cesar Neira # Vendor Homepage: entvtnetcn/ # Affected Firmware Versions: 3143B 3143P 316P-1021-03 3175B-1021-00 317B-1021-00 3181B-1021-00 3183B-1 ...
TVT TD-2308SS-B DVR suffers from a directory traversal vulnerability ...