#VU14816 Arbitrary file upload in NUUO NVRmini 2 - CVE-2018-11523
Published: September 20, 2018 / Updated: June 17, 2021
NUUO NVRmini 2
NUUO Inc.
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to software allows upload of arbitrary files to the system in /nuuonvr.php script. A remote unauthenticated attacker can upload arbitrary file (e.g. with ".php" extension) and execute it on the server.