VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows attackers to access arbitrary system files through unvalidated 'ID' parameters. Attackers can exploit multiple Perl scripts like downloadsys.pl to read sensitive files by manipulating directory path traversal in download requests.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-12-24 20:15
Updated : 2025-12-29 15:58
NVD link : CVE-2019-25256
Mitre link : CVE-2019-25256
CVE.ORG link : CVE-2019-25256
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
