Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-9965

EPSS 0.09% · P25
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-9965

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using a directory traversal attack, an unauthorized person can view web server files.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Schneider Electric Pelco VideoXpert Enterprise 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Schneider Electric Pelco VideoXpert Enterprise是法国施耐德电气(Schneider Electric)公司的一套企业视频管理系统。 Schneider Electric Pelco VideoXpert Enterprise 2.1之前的版本中存在目录遍历漏洞。攻击者可利用该漏洞查看Web服务器文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Schneider Electric SEPelco VideoXpert Enterprise Versions 2.0 and prior -

II. Public POCs for CVE-2017-9965

#POC DescriptionSource LinkShenlong Link
1Schneider Electric Pelco VideoXpert Enterprise versions 2.0 and prior contain a directory traversal caused by insufficient input validation, letting unauthorized persons view web server files, exploit requires no authentication. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-9965.yamlPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-9965

登录查看更多情报信息。

Same Patch Batch · Schneider Electric SE · 2018-01-02 · 3 CVEs total

CVE-2017-9964Schneider Electric Pelco VideoXpert Enterprise 路径遍历漏洞
CVE-2017-9966Schneider Electric Pelco VideoXpert Enterprise 访问控制错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2017-9965

No comments yet


Leave a comment