6.4
CVSSv2

CVE-2003-1386

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

AXIS 2400 Video Server 2.00 up to and including 2.33 allows remote malicious users to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file.

Vulnerable Product Search on Vulmon Subscribe to Product

axis 2400 video server 2.0

axis 2400 video server 2.20

axis 2401 video server 2.31

axis 2401 video server 2.32

axis 2401 video server 2.33

axis 2400 video server 2.31

axis 2400 video server 2.32

axis 2400 video server 2.33

axis 2401 video server 2.20

Exploits

source: wwwsecurityfocuscom/bid/6980/info It has been reported that the Axis Video Server does not properly secure sensitive information Because of this, an attacker may be able to gather details about server operation and traffic that could lead to further attacks wwwexamplecom/support/messages ...