Remote Command Execution Vulnerability in VLC Media Player by VideoLAN
CVE-2013-3564
5.3MEDIUM
Summary
The VLC Media Player prior to version 2.0.7 contains a security flaw in its web interface, which lacks proper access controls. This vulnerability enables unauthorized remote attackers to execute commands, such as viewing directory listings, without requiring authentication. The absence of access restrictions can lead to potential information disclosure and unauthorized control over the application, making it critical for users to upgrade to the latest version to mitigate these risks.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved