Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/153191/Supra-Smart-Cloud-TV-Remote-File-Inclusion.html | Exploit Third Party Advisory VDB Entry |
https://drive.google.com/file/d/1ZVHn_bPE-3kqYd2D-3AJpXZdd4dlmzVh/view?usp=sharing | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-06-07T14:51:07
Updated: 2019-06-07T14:51:07
Reserved: 2019-05-30T00:00:00
Link: CVE-2019-12477
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-06-07T15:29:01.480
Modified: 2019-06-11T14:33:03.263
Link: CVE-2019-12477
JSON object: View
Redhat Information
No data.
CWE