CVE-2023-53773
MEDIUMMiniDVBLinux < 5.4 - Unauthenticated Live Stream Snapshot Generation via tv_action.sh
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53773. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates an unauthenticated stream disclosure vulnerability in MiniDVBLinux 5.4 by calling /tpl/tv_action.sh, which generates a snapshot accessible at /var/www/images/tv.jpg. This allows an attacker to capture live stream images without authentication.
Description
MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attackers to generate live stream snapshots through the Simple VDR Protocol. Attackers can request /tpl/tv_action.sh to create and retrieve a live TV screenshot stored in /var/www/images/tv.jpg without authentication.
Exploits (1)
The exploit demonstrates an unauthenticated stream disclosure vulnerability in MiniDVBLinux 5.4 by calling /tpl/tv_action.sh, which generates a snapshot accessible at /var/www/images/tv.jpg. This allows an attacker to capture live stream images without authentication.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N