Vulnerabilities > CVE-2005-1552 - Unspecified vulnerability in Geovision Digital Surveillance System 6.0.4/6.1/7.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
geovision
nessus

Summary

GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, which may allow remote attackers to gain sensitive information via a direct request to the image.

Nessus

NASL familyWeb Servers
NASL idGEOHTTPSERVER_UNAUTHORIZED_IMAGE_ACCESS.NASL
descriptionThe GeoVision Digital Surveillance System installed on the remote host suffers from a vulnerability that enables anyone to bypass authentication and view JPEG images stored on the server by calling them directly.
last seen2020-06-01
modified2020-06-02
plugin id18220
published2005-05-10
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/18220
titleGeoHttpServer Unauthorized Image Access Vulnerability