Record summary

CVE-2018-19365 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted HTTP request.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 26, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWowza Streaming Engine Manager 4.7.4.01 - Directory TraversalCVSS 9.1

Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted HTTP request to the REST API.

Impact

An attacker can exploit this vulnerability to read arbitrary files on the server, potentially leading to unauthorized access or disclosure of sensitive information.

Remediation

Upgrade to the latest version of Wowza Streaming Engine Manager or apply the necessary patches to fix the directory traversal vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2018cvewowzalfivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CPE: cpe:2.3:a:wowza:streaming_engine:4.7.4.0.1:*:*:*:*:*:*:*
Shodan: http.title:"manager" product:"wowza streaming engine"
Shodan: cpe:"cpe:2.3:a:wowza:streaming_engine"
FOFA: title="manager" product:"wowza streaming engine"
Google: intitle:"manager" product:"wowza streaming engine"

Source: ProjectDiscovery

References

3