{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/za-internet-gmbh/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["C-MOR Video Surveillance (\u003c= 6.0104)"],"_cs_severities":["high"],"_cs_tags":["webapps","directory-traversal","cve-2026-51134","surveillance","web-application-vulnerability","xss"],"_cs_type":"threat","_cs_vendors":["za-internet GmbH","za-internet"],"content_html":"\u003cp\u003eC-MOR Video Surveillance (versions \u0026lt;= 6.0104) by za-internet GmbH contains a directory traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the underlying system. The vulnerability exists within the show-movies.pml component, which fails to properly sanitize the 'cam' input parameter. By supplying specially crafted HTTP requests containing traversal sequences (e.g., '../'), an attacker can escape the intended web application directory and access sensitive system files. This vulnerability, tracked as CVE-2026-51134, is documented with a public proof-of-concept exploit. Given the nature of video surveillance systems, unauthorized access to system files could lead to the exposure of credentials, configuration data, or other sensitive information, facilitating further system compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing C-MOR Video Surveillance instances.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET request targeting the 'show-movies.pml' endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects directory traversal sequences (../) into the 'cam' parameter within the URL query string.\u003c/li\u003e\n\u003cli\u003eThe vulnerable web application processes the request without sanitizing the input path.\u003c/li\u003e\n\u003cli\u003eThe server-side code resolves the path relative to the root directory or unintended application directories.\u003c/li\u003e\n\u003cli\u003eThe application returns the contents of the requested file (e.g., /etc/passwd) in the HTTP response body.\u003c/li\u003e\n\u003cli\u003eAttacker parses the response to exfiltrate system configuration or sensitive data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to retrieve arbitrary files from the filesystem of the C-MOR surveillance server. This can lead to the exposure of sensitive configuration files, system credentials, or other internal application data. The scope of impact is limited to the server running the vulnerable software, but potentially provides attackers with sufficient information to elevate privileges or pivot further into the internal network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch C-MOR Video Surveillance to the latest version immediately if a fix is provided by za-internet GmbH; if no patch is available, restrict access to the web interface via network controls.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect attempts to access sensitive system files via the show-movies.pml component.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous requests containing directory traversal sequences (e.g., ../) directed at the show-movies.pml script.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-31T14:04:44Z","date_published":"2026-08-31T14:04:31Z","id":"https://feed.craftedsignal.io/briefs/2026-08-c-mor-traversal/","summary":"C-MOR Video Surveillance versions up to 6.0104 are vulnerable to an unauthenticated directory traversal attack in the show-movies.pml component, allowing remote attackers to read arbitrary files.","title":"C-MOR Video Surveillance Directory Traversal Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-c-mor-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Za-Internet GmbH","version":"https://jsonfeed.org/version/1.1"}