Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-14064. PoCs published by Miguel Mendez Z. A Nuclei detection template is also available.
AI-analyzed exploit summary The provided text describes a Local File Inclusion (LFI) vulnerability in VelotiSmart Wifi devices (B380) via directory traversal in the uc-http service 1.0.0. The exploit allows unauthorized access to sensitive files like /etc/passwd by manipulating the URL path.
Description
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80.
Exploits (1)
The provided text describes a Local File Inclusion (LFI) vulnerability in VelotiSmart Wifi devices (B380) via directory traversal in the uc-http service 1.0.0. The exploit allows unauthorized access to sensitive files like /etc/passwd by manipulating the URL path.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H