7.5
CVSSv3

CVE-2023-6893

Published: 17/12/2023 Updated: 11/04/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as problematic. Affected by this issue is some unknown functionality of the file /php/exportrecord.php. The manipulation of the argument downname with the input C:\ICPAS\Wnmp\WWW\php\conversion.php leads to path traversal. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-248252.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hikvision intercom_broadcast_system

Github Repositories

不定期更新POC和Nuclei脚本

主要收集一些 poc 以及对应的 fofa 语法和 nuclei 脚本 当前漏洞数:19 声明 由于传播、利用本文所提供的信息而造成的任何直接或者间接的后果及损失,均由使用者本人负责,作者不为此承担任何责任。所涉及工具来自网络,安全性自测。 近期更新 2024-01-11 金和OA SAP_B1Config 未授权访问