Description
MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive system files through the 'file' GET parameter. Attackers can exploit the about page by supplying file paths to disclose arbitrary file contents on the affected device.
Problem types
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
<=5.4
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/51097 (ExploitDB-51097)
www.minidvblinux.de (MiniDVBLinux Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5719.php (Zero Science Lab Disclosure (ZSL-2022-5719))
www.vulncheck.com/...-file-read-vulnerability-via-about-page (VulnCheck Advisory: MiniDVBLinux 5.4 Arbitrary File Read Vulnerability via About Page)