Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109999. PoCs published by LiquidWorm.
AI-analyzed exploit summary The vulnerability involves a local file disclosure flaw in NUUO NVRmini devices, where the 'css' parameter in 'css_parser.php' is improperly sanitized, allowing attackers to read arbitrary files. The provided code includes HTTP request/response examples demonstrating the exploit.
Description
NUUO NVRmini 2 3.0.8 - Local File Disclosure
Exploits (1)
The vulnerability involves a local file disclosure flaw in NUUO NVRmini devices, where the 'css' parameter in 'css_parser.php' is improperly sanitized, allowing attackers to read arbitrary files. The provided code includes HTTP request/response examples demonstrating the exploit.