Description
VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows attackers to execute system commands with root privileges. Attackers can exploit the vulnerability through a cross-site request forgery (CSRF) mechanism to gain unauthorized system access.
Problem types
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
1.40.0.15
2.10.0.5
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5455.php
www.video-flow.com
www.exploit-db.com/exploits/44387 (ExploitDB-44387)
www.video-flow.com (VideoFlow Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5455.php (Zero Science Lab Disclosure (ZSL-2018-5455))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.