10
CVSSv2

CVE-2003-0240

Published: 09/06/2003 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The web-based administration capability for various Axis Network Camera products allows remote malicious users to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).

Vulnerable Product Search on Vulmon Subscribe to Product

axis 2110 network camera

axis 2120 network camera

axis 2100 network camera

axis 250s video server

axis 2130 ptz network camera

axis 2400 video server

axis 2401 video server

axis 2420 network camera

axis 2460 network dvr

Exploits

source: wwwsecurityfocuscom/bid/7652/info A vulnerability has been discovered in various Axis Communications products By making a request for a specially formatted URL, it may be possible for remote users to access the administrative configuration interface without being prompted for authentication camera-ip//admin/adminshtml ...