Vulnerability Name: | CVE-2013-3564 (CCN-176313) | ||||||||||||
Assigned: | 2013-06-10 | ||||||||||||
Published: | 2013-06-10 | ||||||||||||
Updated: | 2020-02-12 | ||||||||||||
Summary: | The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-3564 Source: CCN Type: VideoLAN Web site Free multimedia solutions for all OS! - VideoLAN Source: XF Type: UNKNOWN videolan-cve20133564-sec-bypass(176313) Source: CCN Type: Trustwave SpiderLabs Security Advisory TWSL2013-007 Multiple Vulnerabilities in VLC Media Player - Web Interface Source: MISC Type: Third Party Advisory https://www3.trustwave.com/spiderlabs/advisories/TWSL2013-007.txt | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |