XtreamerPro is a popular media-player and streamer with
an optional web interface management
XtreamerPro suffers from a directory traversal with
appending the '/' character in the HTTP GET method of the
affected host address. XtreamerPro also prone to an
authentication bypass vulnerability. This vulnerability
can be exploited by remote attackers to access sensitive
data on the server without being authenticated. The attacker
can also upload files to any location on the server, without
being authenticated, using a multipart/form-data post.
Tested on: ver 2.6.0 + ver 2.7.0
Hello ichen78,
I see that you are very good hacker for this things, i wold like to ask you a question. Since many days i am looking for a solution to a problem (actually is a wish!).
How can I access into my Xtreamer Pro directly from the terminal of my macbook using ssh or ftp?
Do you know if it is possible and how can i do it.
Thank you very much anyway.
biondbiond 1 month ago