Record summary

CVE-2017-5982 has a selected CVSS score of 7.5 (high); EIP currently links 2 catalogued exploits and 1 Nuclei template.

Description

Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2
Nuclei templates
1

Proofs of concept

2

Catalogued exploits

ExploitDBKodi 17.1 - Arbitrary File DisclosureExploitDB exploitby Eric FlokstraNot analyzed1 file
ExploitDB

PoC details
MetasploitKodi 17.0 Local File Inclusion VulnerabilityMetasploit auxiliary PoCby Eric Flokstra +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHKodi 17.1 - Local File InclusionCVSS 7.5

Kodi 17.1 is vulnerable to local file inclusion vulnerabilities because of insufficient validation of user input.

Impact

Unauthenticated attackers can read arbitrary files on the system, potentially exposing sensitive information, credentials, and configuration files.

Remediation

Upgrade Kodi to a version that is not affected by the CVE-2017-5982 vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2017cvekodilfiedbvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:kodi:kodi:17.1:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

6