CVE Feed

    Dashboard / CVE / CVE-2019-8389

    CVE-2019-8389

    A file-read vulnerability was identified in the Wi-Fi transfer feature of Musicloud 1.6. By default, the application runs a transfer service on port 8080, accessible by everyone on the same Wi-Fi network. An attacker can send the POST parameters downfiles and cur-folder (with a crafted ../ payload) to the download.script endpoint. This will create a MusicPlayerArchive.zip archive that is publicly accessible and includes the content of any requested file (such as the /etc/passwd file).

    Published:Feb 17, 2019
    Last Modified:Nov 21, 2024
    EPS:Feb 17, 2019
    EPSS Score:0.04841
    CVSS Score:8.1

    Affected Products

    Vendor
    Musicloud Project
    Product
    Musicloud

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High