CVE-2021-27197

DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is triggered when a remote attacker crafts an HTML page (e.g., with "OBJECT classid=" and "") to overwrite arbitrary files.
Configurations

Configuration 1

cpe:2.3:a:pelco:digital_sentry_server:*:*:*:*:*:*:*:*

Information

Published : 2021-02-12 04:15

Updated : 2021-02-19 07:33


NVD link : CVE-2021-27197

Mitre link : CVE-2021-27197

Products Affected
No products.
CWE