Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2017-15885
Disclosure Date: October 25, 2017 (last updated November 26, 2024)
Reflected XSS in the web administration portal on the Axis 2100 Network Camera 2.03 allows an attacker to execute arbitrary JavaScript via the conf_Layout_OwnTitle parameter to view/view.shtml. NOTE: this might overlap CVE-2007-5214.
0
Attacker Value
Unknown
CVE-2017-12413
Disclosure Date: August 04, 2017 (last updated November 26, 2024)
AXIS 2100 devices 2.43 have XSS via the URI, possibly related to admin/admin.shtml.
0
Attacker Value
Unknown
CVE-2017-9828
Disclosure Date: June 23, 2017 (last updated November 26, 2024)
'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected. An attack uses shell metacharacters in the senderemail parameter.
0
Attacker Value
Unknown
CVE-2017-9829
Disclosure Date: June 23, 2017 (last updated November 26, 2024)
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected.
0
Attacker Value
Unknown
CVE-2015-8257
Disclosure Date: May 02, 2017 (last updated November 26, 2024)
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml.
0
Attacker Value
Unknown
CVE-2015-8256
Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
0
Attacker Value
Unknown
CVE-2014-9238
Disclosure Date: December 03, 2014 (last updated October 05, 2023)
D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to obtain the installation path via the file parameter to cgi-bin/sddownload.cgi, as demonstrated by a / (forward slash) character.
0
Attacker Value
Unknown
CVE-2014-9234
Disclosure Date: December 03, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in cgi-bin/sddownload.cgi in D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
0
Attacker Value
Unknown
CVE-2014-8756
Disclosure Date: October 17, 2014 (last updated October 05, 2023)
The NcrCtl4.NcrNet.1 control in Panasonic Network Camera Recorder before 4.04R03 allows remote attackers to execute arbitrary code via a crafted GetVOLHeader method call, which writes null bytes to an arbitrary address.
0
Attacker Value
Unknown
CVE-2011-5261
Disclosure Date: February 12, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the pageTitle parameter to admin/showReport.shtml.
0