Loading
Generated remediation guidance and an executive summary. No account required.
VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows authenticated attackers to disclose arbitrary files by injecting path traversal sequences in the ID parameter. Attackers can submit requests to downloadsys.pl, download_xml.pl, download.pl, downloadmib.pl, or downloadFile.pl with directory traversal payloads to read sensitive system files like /etc/passwd.
No affected products information available.
Use CWE-22 to widen CVE-2018-25311 into its surrounding weakness, vendor, and product context.