Back to search
CVE-2004-2425
Published: Aug 18, 2005
Modified: Aug 8, 2024
PUBLISHED
Description
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
asix-command-execution(17076)
vdb-entry
x_refsource_XF
9121
vdb-entry
x_refsource_OSVDB
11011
vdb-entry
x_refsource_BID
20040831 Axis Network Camera and Video Server Security Advisory
mailing-list
x_refsource_FULLDISC
12353
third-party-advisory
x_refsource_SECUNIA
20040822 [PoC] Nasty bug(s) found in Axis Network Camera/Video Servers
mailing-list
x_refsource_FULLDISC
1011056
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now