5

CVE-2004-2426

Exploit

Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a ..  (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities, such as modifying files using editcgi.cgi.

Data is provided by the National Vulnerability Database (NVD)
Axis2100 Network Camera Version2.12
Axis2100 Network Camera Version2.30
Axis2100 Network Camera Version2.31
Axis2100 Network Camera Version2.32
Axis2100 Network Camera Version2.33
Axis2100 Network Camera Version2.34
Axis2100 Network Camera Version2.40
Axis2100 Network Camera Version2.41
Axis2110 Network Camera Version2.12
Axis2110 Network Camera Version2.30
Axis2110 Network Camera Version2.31
Axis2110 Network Camera Version2.32
Axis2110 Network Camera Version2.34
Axis2110 Network Camera Version2.40
Axis2110 Network Camera Version2.41
Axis2120 Network Camera Version2.12
Axis2120 Network Camera Version2.30
Axis2120 Network Camera Version2.31
Axis2120 Network Camera Version2.32
Axis2120 Network Camera Version2.34
Axis2120 Network Camera Version2.40
Axis2120 Network Camera Version2.41
Axis2130 Ptz Network Camera Version2.30
Axis2130 Ptz Network Camera Version2.31
Axis2130 Ptz Network Camera Version2.32
Axis2130 Ptz Network Camera Version2.34
Axis2130 Ptz Network Camera Version2.40
Axis230 Mpeg2 Video Server Version3.11
Axis2400 Video Server Version1.1
Axis2400 Video Server Version1.2
Axis2400 Video Server Version1.10
Axis2400 Video Server Version1.11
Axis2400 Video Server Version1.12
Axis2400 Video Server Version1.15
Axis2400 Video Server Version2.0
Axis2400 Video Server Version2.20
Axis2400 Video Server Version2.30
Axis2400 Video Server Version2.31
Axis2400 Video Server Version2.32
Axis2400 Video Server Version2.33
Axis2400 Video Server Version2.34
Axis2400 Video Server Version3.11
Axis2400 Video Server Version3.12
Axis2401 Video Server Version1.0_1
Axis2401 Video Server Version1.15
Axis2401 Video Server Version2.20
Axis2401 Video Server Version2.30
Axis2401 Video Server Version2.31
Axis2401 Video Server Version2.32
Axis2401 Video Server Version2.33
Axis2401 Video Server Version2.34
Axis2401 Video Server Version3.12
Axis2401 Video Server Version3.13
Axis2411 Video Server Version3.12
Axis2411 Video Server Version3.13
Axis2420 Network Camera Version2.12
Axis2420 Network Camera Version2.30
Axis2420 Network Camera Version2.31
Axis2420 Network Camera Version2.32
Axis2420 Network Camera Version2.33
Axis2420 Network Camera Version2.34
Axis2420 Network Camera Version2.40
Axis2420 Network Camera Version2.41
Axis2420 Video Server Version2.32
Axis2420 Video Server Version2.34
Axis2460 Network Dvr Version3.10
Axis2460 Network Dvr Version3.11
Axis2490 Serial Server Version2.11.3
Axis250s Video Server Version3.03
Axis250s Video Server Version3.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.87% 0.824
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N