Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy.
[
{
"deprecated": false,
"source": "https://github.com/plutinosoft/platinum/commit/9a4ceaccb1585ec35c45fd8e2585538fff6a865e",
"id": "CVE-2020-19858-0e95dbfd",
"signature_type": "Line",
"target": {
"file": "Source/Core/PltHttpServer.cpp"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"89715038123318133197712509297366048175",
"154003430596154717838436493955882382533",
"244448909281444007921412754850304295595",
"199032240060906064054520983253250468326"
]
}
},
{
"deprecated": false,
"source": "https://github.com/plutinosoft/platinum/commit/9a4ceaccb1585ec35c45fd8e2585538fff6a865e",
"id": "CVE-2020-19858-e498f1ea",
"signature_type": "Function",
"target": {
"file": "Source/Core/PltHttpServer.cpp",
"function": "PLT_HttpServer::ServeFile"
},
"signature_version": "v1",
"digest": {
"function_hash": "204709126429326389787337362557031989060",
"length": 1664.0
}
}
]