Update eyelock-nano-lfd.yaml

patch-1
Prince Chaddha 2021-08-16 16:40:42 +05:30 committed by GitHub
parent af4f29ab03
commit d3a379e112
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 3 additions and 3 deletions

View File

@ -2,11 +2,11 @@ id: eyelock-nano-lfd
info:
name: EyeLock nano NXT 3.5 - Local File Disclosure
description:
author: geeknik
reference: https://www.zeroscience.mk/codes/eyelock_lfd.txt
severity: high
tags: eyelock,lfd,traversal,iot,biometrics
description: nano NXT suffers from a file disclosure vulnerability when input passed thru the 'path' parameter to 'logdownload.php' script is not properly verified before being used to read files. This can be exploited to disclose contents of files from local resources.
reference: https://www.zeroscience.mk/codes/eyelock_lfd.txt
tags: iot,lfi,eyelock
requests:
- method: GET