CVE-2007-5212 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware before 2.43 allow remote attackers to inject arbitrary web script or HTML via (1) parameters associated with saved settings as demonstrated by the conf_SMTP_MailServer1 parameter to ServerManager.srv; or (2) the subpage parameter to wizard/first/wizard_main_first.shtml. NOTE: an attacker can leverage a CSRF vulnerability to modify saved settings.
Reference
http://osvdb.org/38795 http://osvdb.org/38796 http://securityreason.com/securityalert/3188 http://www.procheckup.com/Vulnerability_Axis_2100_research.pdf http://www.securityfocus.com/archive/1/480995/100/0/threaded http://www.securityfocus.com/bid/25837
Share on: