Vulnerabilities > CVE-2004-2427 - Unspecified vulnerability in Axis products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi, (3) admin/serverreport.cgi, and (4) admin/paramlist.cgi, modify system information via (5) setparam.cgi and (6) factorydefault.cgi, or (7) cause a denial of service (reboot) via restart.cgi.
Vulnerable Configurations
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0948.html
- http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0948.html
- http://securitytracker.com/id?1011056
- http://securitytracker.com/id?1011056
- http://www.osvdb.org/9123
- http://www.osvdb.org/9123
- http://www.osvdb.org/9125
- http://www.osvdb.org/9125
- http://www.osvdb.org/9126
- http://www.osvdb.org/9126
- http://www.osvdb.org/9127
- http://www.osvdb.org/9127
- http://www.osvdb.org/9128
- http://www.osvdb.org/9128
- http://www.osvdb.org/9129
- http://www.osvdb.org/9129
- http://www.osvdb.org/9130
- http://www.osvdb.org/9130