漏洞描述 ViolaDVR存在任意文件读取,在登录时,POST请求中有很多字段供使用,其中FILEFAIL参数用于跳转页面显示登陆失败时的信息。由于程序没有对用户的输入做足够的过滤,在用户登陆失败时,攻击者通过修改FILEFAIL标签的值即可重定向到任意文件,实现任意文件读取。
相关漏洞推荐 POC CVE-2021-41419: QVIS NVR/DVR - Remote Code Execution POC CVE-2018-15745: Argus Surveillance DVR 4.0.0.0 - Local File Inclusion POC CVE-2018-9995: TBK DVR4104/DVR4216 Devices - Authentication Bypass POC CVE-2021-42071: Visual Tools DVR VX16 4.2.28.0 - Unauthenticated OS Command Injection POC CVE-2024-7339: TVT DVR Sensitive Device - Information Disclosure POC CVE-2018-9995: DVR Authentication Bypass POC avtech-dvr-exposure: Avtech AVC798HA DVR Information Exposure POC CVE-2013-4982: AVTECH DVR - Login Verification Code Bypass POC avtech-dvr-exposure: AVTECH AVC798HA DVR - Information Exposure POC qvisdvr-deserialization-rce: QVISDVR JSF Deserialization - Remote Code Execution POC intelbras-dvr-unauth: Intelbras DVR - Unrestricted Access POC avtech-dvr-ssrf: AVTECH DVR - SSRF POC commax-credentials-disclosure: COMMAX Smart Home Ruvie CCTV Bridge DVR - RTSP Credentials Disclosure