Description
PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting relative path sequences in GET requests. Attackers can use path traversal sequences ../../../../../../../../../../../../etc/passwd to access sensitive system files outside the intended directory.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
Berk Dusunur
References
www.exploit-db.com/exploits/45248 (ExploitDB-45248)
www.softpedia.com/get/System/File-Management/Pc-Viewer.shtml (Product Reference)
www.vulncheck.com/...000-directory-traversal-via-get-request (VulnCheck Advisory: PCViewer vt1000 Directory Traversal via GET Request)