CVE-2017-18263

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
28/04/2018
Last modified:
05/06/2018

Description

Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:seagate:personal_cloud_firmware:*:*:*:*:*:*:*:* 4.3.18.4 (excluding)
cpe:2.3:h:seagate:personal_cloud:-:*:*:*:*:*:*:*