Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-15038. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates an arbitrary file deletion vulnerability in NUUO NVRmini 2 due to unsanitized input in the 'filename' parameter of 'deletefile.php'. The PHP script directly passes user input to the 'unlink' function, allowing deletion of files via absolute paths or directory traversal.
Description
A vulnerability, which was classified as critical, was found in NUUO NVRmini 2 up to 3.0.8. Affected is an unknown function of the file /deletefile.php. The manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258780.
Exploits (1)
The exploit demonstrates an arbitrary file deletion vulnerability in NUUO NVRmini 2 due to unsanitized input in the 'filename' parameter of 'deletefile.php'. The PHP script directly passes user input to the 'unlink' function, allowing deletion of files via absolute paths or directory traversal.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L