Remote Command Execution Vulnerability in VLC Media Player by VideoLAN
CVE-2013-3564
5.3MEDIUM
What is CVE-2013-3564?
The VLC Media Player prior to version 2.0.7 contains a security flaw in its web interface, which lacks proper access controls. This vulnerability enables unauthorized remote attackers to execute commands, such as viewing directory listings, without requiring authentication. The absence of access restrictions can lead to potential information disclosure and unauthorized control over the application, making it critical for users to upgrade to the latest version to mitigate these risks.