CVE-2023-53772
HIGHMiniDVBLinux 5.4 - Arbitrary File Read via About Page File Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53772. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file read vulnerability in MiniDVBLinux 5.4 by manipulating the 'file' GET parameter to disclose sensitive system files. It uses a simple HTTP request to fetch the file content and parses the response to extract the file data.
Description
MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive system files through the 'file' GET parameter. Attackers can exploit the about page by supplying file paths to disclose arbitrary file contents on the affected device.
Exploits (1)
This exploit demonstrates an arbitrary file read vulnerability in MiniDVBLinux 5.4 by manipulating the 'file' GET parameter to disclose sensitive system files. It uses a simple HTTP request to fetch the file content and parses the response to extract the file data.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N