AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2003-12-30 21:00
Updated : 2017-07-28 18:29
NVD link : CVE-2003-1386
Mitre link : CVE-2003-1386
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
axis
- 2400_video_server
- 2401_video_server