mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-28 09:12:08 +00:00
1.1 KiB
1.1 KiB
CVE-2018-1149
Description
cgi_system in NUUO's NVRMini2 3.8.0 and below allows remote attackers to execute arbitrary code via crafted HTTP requests.
POC
Reference
- https://github.com/tenable/poc/tree/master/nuuo/nvrmini2
- https://github.com/tenable/poc/tree/master/nuuo/nvrmini2
- https://www.nuuo.com/backend/CKEdit/upload/files/NUUO_NVRsolo_v3_9_1_Release%20note.pdf
- https://www.nuuo.com/backend/CKEdit/upload/files/NUUO_NVRsolo_v3_9_1_Release%20note.pdf
- https://www.tenable.com/security/research/tra-2018-25
- https://www.tenable.com/security/research/tra-2018-25