Description
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T17:18:02.190Z
Reserved: 2017-06-23T00:00:00.000Z
Link: CVE-2017-9833
No data.
Status : Modified
Published: 2017-06-24T02:29:00.207
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-9833
No data.
OpenCVE Enrichment
No data.
Weaknesses