Vulnerabilities > CVE-2003-0240 - Authentication Bypass vulnerability in Axis Network Camera HTTP

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
axis
critical
exploit available

Summary

The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).

Vulnerable Configurations

Part Description Count
Hardware
Axis
51

Exploit-Db

descriptionAxis Network Camera 2.x HTTP Authentication Bypass Vulnerability. CVE-2003-0240. Remote exploit for hardware platform
idEDB-ID:22626
last seen2016-02-02
modified2003-05-27
published2003-05-27
reporterJuliano Rizzo
sourcehttps://www.exploit-db.com/download/22626/
titleAxis Network Camera 2.x HTTP Authentication Bypass Vulnerability

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/31168/core.axis.txt
idPACKETSTORM:31168
last seen2016-12-05
published2003-05-28
reporterJuliano Rizzo
sourcehttps://packetstormsecurity.com/files/31168/core.axis.txt.html
titlecore.axis.txt