CVE-2018-19365
wowza streaming_engine Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2018-19365 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.
Description
The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted HTTP request.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 26, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
streaming_engineBrowse wowza / streaming_engine | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALWowza Streaming Engine Manager 4.7.4.01 - Directory TraversalCVSS 9.1
Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted HTTP request to the REST API.
Impact
An attacker can exploit this vulnerability to read arbitrary files on the server, potentially leading to unauthorized access or disclosure of sensitive information.
Remediation
Upgrade to the latest version of Wowza Streaming Engine Manager or apply the necessary patches to fix the directory traversal vulnerability.
Source: ProjectDiscovery