mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-03 04:38:03 +02:00
18 lines
728 B
Markdown
18 lines
728 B
Markdown
### [CVE-2020-23490](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-23490)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can exploit this issue to read an arbitrary file on the server. Which could leak database credentials or other sensitive information such as /etc/passwd file.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
No PoCs from references.
|
|
|
|
#### Github
|
|
- https://github.com/ahussam/AVideo3xploit
|
|
|