Vulnerabilities > CVE-2004-2425 - Unspecified vulnerability in Axis products

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
axis
exploit available

Summary

Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.

Vulnerable Configurations

Part Description Count
Hardware
Axis
74

Exploit-Db

descriptionAxis Network Camera 2.x And Video Server 1-3 virtualinput.cgi Arbitrary Command Execution. CVE-2004-2425. Webapps exploit for cgi platform
idEDB-ID:24400
last seen2016-02-02
modified2004-08-23
published2004-08-23
reporterbashis
sourcehttps://www.exploit-db.com/download/24400/
titleAxis Network Camera 2.x And Video Server 1-3 - virtualinput.cgi Arbitrary Command Execution