Record summary

CVE-2022-25216 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to http://<IP_ADDRESS>:32080/download/<URL_ENCODED_PATH>.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

DVDFab 12 Player / PlayerFab

CVE List6.2.1.0 - 7.0.0.5affected

Nuclei templates

1
ProjectDiscoveryHIGHDVDFab 12 Player/PlayerFab - Local File InclusionCVSS 7.5

DVDFab 12 Player/PlayerFab is susceptible to local file inclusion which allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access.

Impact

The vulnerability allows an attacker to include arbitrary local files, potentially leading to unauthorized access, information disclosure.

Remediation

Apply the latest patch or update from the vendor to fix the vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2022dvdFablfilfrtenabledvdfabvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:dvdfab:12_player:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2