Axis Network Camera 2,40 e precedenti, e Video Server 3.12 e precedenti, consente agli aggressori remoti di eseguire comandi arbitrari con accento ( `) ed eventualmente altri metacaratteri della shell nella stringa di query per virtualinput.cgi. |
http://www.securityfocus.com/bid/11011 http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0948.html http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1282.html http://www.osvdb.org/9121 http://securitytracker.com/id?1011056 http://secunia.com/advisories/12353 https://exchange.xforce.ibmcloud.com/vulnerabilities/17076 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2425 |
Vulnerabilità: CVE-2004-2425
