 |
 |
 |
 |
|
DiViS DVR System web-server which fingerprints as Techno Vision Security System has Directory Traversal vulnerability.
Application: Chance-i DiViS DVR System web-server (part of DiViS DVR)
Versions Affected: 2.0 (DiViS DVR less 12.0.0)
Vendor URL: http://www.divisdvr.com/
Bug: Directory Traversal File Download
Exploits: YES
Reported: 13.03.2009
Second Reported: 20.03.2009
Vendor response: 12.05.2009
Solution: NONE
Date of Public Advisory: 09.04.2009
Author: Digital Security Research Group [DSecRG] (research [at] dsecrg [dot] com)
Details
*******
A directory traversal vulnerability was found in DiViS DVR System web-server.
Successful exploitation of these issues allows remote attackers to access the contents of arbitrary files.
Example:
http://[server]/../../../../../../../boot.ini
Solution:
*********
Vendor response:
We will revise our next version software to resolve this issue. Our next version is 12.0.0 which is expected to be released soon.
About
*****
Digital Security is leading IT security company in Russia, providing information security consulting, audit and penetration testing services, risk analysis and ISMS-related services and certification for ISO/IEC 27001:2005 and PCI DSS standards.
Digital Security Research Group focuses on web application and database security problems with vulnerability reports, advisories and whitepapers posted regularly on our website.
Contact: research [at] dsecrg [dot] com
http://www.dsecrg.com
http://www.dsec.ru
|
|
 |
 |
 |
 |
|
|
|