CVE-2016-5639
CVE-2016-5639
Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter.
Affected products
n/a · n/apublic PoCs found — 3
githubgithub.com/xfox64x/CVE-2016-5639★ 2cve_referencewww.exploit-db.com/exploits/40813/unverifiedexploitdbwww.exploit-db.com/exploits/40813unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →