From d3a379e11239fcf05ad7e59e4ffed38cfdb3ef43 Mon Sep 17 00:00:00 2001 From: Prince Chaddha Date: Mon, 16 Aug 2021 16:40:42 +0530 Subject: [PATCH] Update eyelock-nano-lfd.yaml --- vulnerabilities/other/eyelock-nano-lfd.yaml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/vulnerabilities/other/eyelock-nano-lfd.yaml b/vulnerabilities/other/eyelock-nano-lfd.yaml index 2a9c255fd8..7e05dfc26c 100644 --- a/vulnerabilities/other/eyelock-nano-lfd.yaml +++ b/vulnerabilities/other/eyelock-nano-lfd.yaml @@ -2,11 +2,11 @@ id: eyelock-nano-lfd info: name: EyeLock nano NXT 3.5 - Local File Disclosure - description: author: geeknik - reference: https://www.zeroscience.mk/codes/eyelock_lfd.txt severity: high - tags: eyelock,lfd,traversal,iot,biometrics + description: nano NXT suffers from a file disclosure vulnerability when input passed thru the 'path' parameter to 'logdownload.php' script is not properly verified before being used to read files. This can be exploited to disclose contents of files from local resources. + reference: https://www.zeroscience.mk/codes/eyelock_lfd.txt + tags: iot,lfi,eyelock requests: - method: GET