Vulnerability Description
Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Seagate | Personal Cloud Firmware | < 4.3.18.4 |
| Seagate | Personal Cloud | - |
Related Weaknesses (CWE)
References
- https://packetstormsecurity.com/files/147274/Seagate-Media-Server-Path-TraversalThird Party AdvisoryVDB Entry
- https://sumofpwn.nl/advisory/2017/seagate-media-server-path-traversal-vulnerabilExploitThird Party Advisory
- https://packetstormsecurity.com/files/147274/Seagate-Media-Server-Path-TraversalThird Party AdvisoryVDB Entry
- https://sumofpwn.nl/advisory/2017/seagate-media-server-path-traversal-vulnerabilExploitThird Party Advisory
FAQ
What is CVE-2017-18263?
CVE-2017-18263 is a vulnerability with a CVSS score of 7.5 (HIGH). Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.
How severe is CVE-2017-18263?
CVE-2017-18263 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18263?
Check the references section above for vendor advisories and patch information. Affected products include: Seagate Personal Cloud Firmware, Seagate Personal Cloud.