The EverFocus EPARA264-16X1 DVR allows unauthenticated remote users to retrieve arbitrary system files that are located outside of the web root through a directory traversal on port 80. Firmware version 1.0.2 is affected.
9498ec7c2d7d5276591c2ebc8509ab56201a5acf174aead7063bf8fe2488c95c