5
CVE-2004-2426
- EPSS 1.87%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities, such as modifying files using editcgi.cgi.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Axis ≫ 2100 Network Camera Version2.12
Axis ≫ 2100 Network Camera Version2.30
Axis ≫ 2100 Network Camera Version2.31
Axis ≫ 2100 Network Camera Version2.32
Axis ≫ 2100 Network Camera Version2.33
Axis ≫ 2100 Network Camera Version2.34
Axis ≫ 2100 Network Camera Version2.40
Axis ≫ 2100 Network Camera Version2.41
Axis ≫ 2110 Network Camera Version2.12
Axis ≫ 2110 Network Camera Version2.30
Axis ≫ 2110 Network Camera Version2.31
Axis ≫ 2110 Network Camera Version2.32
Axis ≫ 2110 Network Camera Version2.34
Axis ≫ 2110 Network Camera Version2.40
Axis ≫ 2110 Network Camera Version2.41
Axis ≫ 2120 Network Camera Version2.12
Axis ≫ 2120 Network Camera Version2.30
Axis ≫ 2120 Network Camera Version2.31
Axis ≫ 2120 Network Camera Version2.32
Axis ≫ 2120 Network Camera Version2.34
Axis ≫ 2120 Network Camera Version2.40
Axis ≫ 2120 Network Camera Version2.41
Axis ≫ 2130 Ptz Network Camera Version2.30
Axis ≫ 2130 Ptz Network Camera Version2.31
Axis ≫ 2130 Ptz Network Camera Version2.32
Axis ≫ 2130 Ptz Network Camera Version2.34
Axis ≫ 2130 Ptz Network Camera Version2.40
Axis ≫ 230 Mpeg2 Video Server Version3.11
Axis ≫ 2400 Video Server Version1.1
Axis ≫ 2400 Video Server Version1.2
Axis ≫ 2400 Video Server Version1.10
Axis ≫ 2400 Video Server Version1.11
Axis ≫ 2400 Video Server Version1.12
Axis ≫ 2400 Video Server Version1.15
Axis ≫ 2400 Video Server Version2.0
Axis ≫ 2400 Video Server Version2.20
Axis ≫ 2400 Video Server Version2.30
Axis ≫ 2400 Video Server Version2.31
Axis ≫ 2400 Video Server Version2.32
Axis ≫ 2400 Video Server Version2.33
Axis ≫ 2400 Video Server Version2.34
Axis ≫ 2400 Video Server Version3.11
Axis ≫ 2400 Video Server Version3.12
Axis ≫ 2401 Video Server Version1.0_1
Axis ≫ 2401 Video Server Version1.15
Axis ≫ 2401 Video Server Version2.20
Axis ≫ 2401 Video Server Version2.30
Axis ≫ 2401 Video Server Version2.31
Axis ≫ 2401 Video Server Version2.32
Axis ≫ 2401 Video Server Version2.33
Axis ≫ 2401 Video Server Version2.34
Axis ≫ 2401 Video Server Version3.12
Axis ≫ 2401 Video Server Version3.13
Axis ≫ 2411 Video Server Version3.12
Axis ≫ 2411 Video Server Version3.13
Axis ≫ 2420 Network Camera Version2.12
Axis ≫ 2420 Network Camera Version2.30
Axis ≫ 2420 Network Camera Version2.31
Axis ≫ 2420 Network Camera Version2.32
Axis ≫ 2420 Network Camera Version2.33
Axis ≫ 2420 Network Camera Version2.34
Axis ≫ 2420 Network Camera Version2.40
Axis ≫ 2420 Network Camera Version2.41
Axis ≫ 2420 Video Server Version2.32
Axis ≫ 2420 Video Server Version2.34
Axis ≫ 2460 Network Dvr Version3.10
Axis ≫ 2460 Network Dvr Version3.11
Axis ≫ 2490 Serial Server Version2.11.3
Axis ≫ 250s Video Server Version3.03
Axis ≫ 250s Video Server Version3.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.87% | 0.824 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|