CVE-2007-5213
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the conf_SMTP_MailServer1 parameter to ServerManager.srv and (2) a hostname change through the conf_Network_HostName parameter on the Network page.
Múltiples vulnerabilidades de falsificación de petición en sitios cruzados (CSRF) en AXIS 2100 Network Camera 2.02 con firmware 2.43 y anteriores permite a atacantes remotos llevar a cabo acciones como administrador, como ha sido demostrado por (1) un cambio del servidor SMTP a través del parámetro conf_SMTP_MailServer1 a ServerManager.srv y (2) un cambio del nombre de máquina a través del parámetro conf_Network_HostName en la página Network.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-10-04 CVE Reserved
- 2007-10-04 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-09-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://osvdb.org/39490 | Vdb Entry | |
http://osvdb.org/39491 | Vdb Entry | |
http://securityreason.com/securityalert/3188 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/480995/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/25837 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://www.procheckup.com/Vulnerability_Axis_2100_research.pdf | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Axis Search vendor "Axis" | 2100 Network Camera Search vendor "Axis" for product "2100 Network Camera" | 2.02 Search vendor "Axis" for product "2100 Network Camera" and version "2.02" | - |
Affected
| ||||||
Axis Search vendor "Axis" | 2100 Network Camera Firmware Search vendor "Axis" for product "2100 Network Camera Firmware" | <= 2.42 Search vendor "Axis" for product "2100 Network Camera Firmware" and version " <= 2.42" | - |
Affected
|