Update eyelock-nano-lfd.yaml
parent
af4f29ab03
commit
d3a379e112
|
@ -2,11 +2,11 @@ id: eyelock-nano-lfd
|
||||||
|
|
||||||
info:
|
info:
|
||||||
name: EyeLock nano NXT 3.5 - Local File Disclosure
|
name: EyeLock nano NXT 3.5 - Local File Disclosure
|
||||||
description:
|
|
||||||
author: geeknik
|
author: geeknik
|
||||||
reference: https://www.zeroscience.mk/codes/eyelock_lfd.txt
|
|
||||||
severity: high
|
severity: high
|
||||||
tags: eyelock,lfd,traversal,iot,biometrics
|
description: nano NXT suffers from a file disclosure vulnerability when input passed thru the 'path' parameter to 'logdownload.php' script is not properly verified before being used to read files. This can be exploited to disclose contents of files from local resources.
|
||||||
|
reference: https://www.zeroscience.mk/codes/eyelock_lfd.txt
|
||||||
|
tags: iot,lfi,eyelock
|
||||||
|
|
||||||
requests:
|
requests:
|
||||||
- method: GET
|
- method: GET
|
||||||
|
|
Loading…
Reference in New Issue