mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 15:15:46 +02:00
772 B
772 B
CVE-2012-0907
Description
Directory traversal vulnerability in the web player in NeoAxis NeoAxis web player 1.4 and earlier allows user-assisted remote attackers to write arbitrary files via a .. (dot dot) in a filename in the neoaxis_web_application_win32.zip ZIP archive.
POC
Reference
- http://aluigi.altervista.org/adv/neoaxis_1-adv.txt
- http://aluigi.altervista.org/adv/neoaxis_1-adv.txt
Github
No PoCs found on GitHub currently.