XtreamerPro hacking - directory traversal & authentication bypass POC

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
2,553
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on May 15, 2011

XtreamerPro is a popular media-player and streamer with
an optional web interface management

XtreamerPro suffers from a directory traversal with
appending the '/' character in the HTTP GET method of the
affected host address. XtreamerPro also prone to an
authentication bypass vulnerability. This vulnerability
can be exploited by remote attackers to access sensitive
data on the server without being authenticated. The attacker
can also upload files to any location on the server, without
being authenticated, using a multipart/form-data post.

Tested on: ver 2.6.0 + ver 2.7.0

  • likes, 0 dislikes

Link to this comment:

Share to:
see all

All Comments (1)

Sign In or Sign Up now to post a comment!
  • Hello ichen78,

    I see that you are very good hacker for this things, i wold like to ask you a question. Since many days i am looking for a solution to a problem (actually is a wish!).

    How can I access into my Xtreamer Pro directly from the terminal of my macbook using ssh or ftp?

    Do you know if it is possible and how can i do it.

    Thank you very much anyway.

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more