airVision NVR Arbitrary File Disclosure and SQL Injection Vulnerabilities
6 Dec. 2012
Summary
airVision NVR is prone to a file-disclosure vulnerability and an SQL-injection vulnerability because it fails to properly sanitize user-supplied input.
Credit:
The information has been provided by pennyGrit.
An remote attacker can exploit these issues to obtain potentially sensitive information from local files on computers running the vulnerable application or modify the logic of SQL queries. A successful exploit may allow the attacker to compromise the software, retrieve information, or modify data; These may aid in further attacks.