The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2003-06-08 21:00
Updated : 2017-07-10 18:29
NVD link : CVE-2003-0240
Mitre link : CVE-2003-0240
JSON object : View
CWE
Products Affected
axis
- 2120_network_camera
- 2100_network_camera
- 2420_network_camera
- 2110_network_camera
- 2401_video_server
- 250s_video_server
- 2400_video_server
- 2130_ptz_network_camera
- 2460_network_dvr