Page 2 of 7 results (0.002 seconds)

CVSS: 6.4EPSS: 3%CPEs: 9EXPL: 1

AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file. • https://www.exploit-db.com/exploits/22296 http://archives.neohapsis.com/archives/bugtraq/2003-02/0377.html http://archives.neohapsis.com/archives/bugtraq/2003-03/0370.html http://www.securityfocus.com/bid/6980 http://www.websec.org/adv/axis2400.txt.html https://exchange.xforce.ibmcloud.com/vulnerabilities/11440 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 10.0EPSS: 2%CPEs: 9EXPL: 1

The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash). Las capacidades de administración basadas en web de varios productos Axis Network Camera permite que atacantes remotos se salten las restricciones de acceso y modifiquen la configuración mediante una petición HTTP a admin/admin.shtml que contiene '//" (dos barras) al principio. • https://www.exploit-db.com/exploits/22626 http://marc.info/?l=bugtraq&m=105406374731579&w=2 http://secunia.com/advisories/8876 http://securitytracker.com/id?1006854 http://www.coresecurity.com/common/showdoc.php?idx=329&idxseccion=10 http://www.kb.cert.org/vuls/id/799060 http://www.osvdb.org/4804 http://www.securityfocus.com/bid/7652 https://exchange.xforce.ibmcloud.com/vulnerabilities/12104 •