Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy.
[
{
"digest": {
"line_hashes": [
"89715038123318133197712509297366048175",
"154003430596154717838436493955882382533",
"244448909281444007921412754850304295595",
"199032240060906064054520983253250468326"
],
"threshold": 0.9
},
"target": {
"file": "Source/Core/PltHttpServer.cpp"
},
"source": "https://github.com/plutinosoft/platinum/commit/9a4ceaccb1585ec35c45fd8e2585538fff6a865e",
"id": "CVE-2020-19858-0e95dbfd",
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"length": 1664.0,
"function_hash": "204709126429326389787337362557031989060"
},
"target": {
"file": "Source/Core/PltHttpServer.cpp",
"function": "PLT_HttpServer::ServeFile"
},
"source": "https://github.com/plutinosoft/platinum/commit/9a4ceaccb1585ec35c45fd8e2585538fff6a865e",
"id": "CVE-2020-19858-e498f1ea",
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
}
]