Cisco's Content Delivery System discloses files
Internet Streamer, a component of Cisco's Content Delivery System that handles the sharing of videos on the internet, discloses arbitrary files outside of the shared web folder to attackers. For instance, it is possible to access password and log files.
To be successful, attackers only need to confront the server component with a suitably crafted URL. Cisco closed the security hole in version 2.5.7, but all older versions are vulnerable. The vendor recommends that users update to version 2.5.9, which also contains other fixes.
(crve)