HIGH
D-Link D-View uploadFile Directory Traversal Arbitrary File Creation Vulnerability
Published May 3, 2024
8.1
HIGHCVSS 3.0
EPSS 74.30%
Description
D-Link D-View uploadFile Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of D-Link D-View. Authentication is required to exploit this vulnerability.
The specific flaw exists within the uploadFile function. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create files in the context of SYSTEM. Was ZDI-CAN-19527.
Affected products
-
- Version DLink D-View8 1.0.2.13StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10332 vendor-advisoryVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-23-717/ x_research-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10332 | vendor-advisoryVendor Advisory | |
| https://www.zerodayinitiative.com/advisories/ZDI-23-717/ | x_research-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner zdi
Published May 3, 2024
Updated Sep 18, 2024
Reserved May 3, 2023
Link CVE-2023-32166
CISA Vulnrichment
Updated May 7, 2024