CVE Vulnerabilities

CVE-2020-7858

Exposure of Information Through Directory Listing

Published: Apr 22, 2021 | Modified: Nov 21, 2024
CVSS 3.x
8.6
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

There is a directory traversing vulnerability in the download page url of AquaNPlayer 2.0.0.92. The IP of the download page url is localhost and an attacker can traverse directories using dot dot sequences(../../) to view host file on the system. This vulnerability can cause information leakage.

Weakness

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Affected Software

Name Vendor Start Version End Version
Aquanplayer Cdnetworks 2.0.0.92 (including) 2.0.0.92 (including)

Potential Mitigations

References