CVE-2003-0240

The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:axis:2100_network_camera:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:2110_network_camera:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:2120_network_camera:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:2130_ptz_network_camera:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:2400_video_server:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:2401_video_server:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:2420_network_camera:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:2460_network_dvr:*:*:*:*:*:*:*:*
cpe:2.3:h:axis:250s_video_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2003-06-09 04:00

Updated : 2023-12-10 10:17


NVD link : CVE-2003-0240

Mitre link : CVE-2003-0240

CVE.ORG link : CVE-2003-0240


JSON object : View

Products Affected

axis

  • 2120_network_camera
  • 2460_network_dvr
  • 2110_network_camera
  • 2130_ptz_network_camera
  • 250s_video_server
  • 2400_video_server
  • 2401_video_server
  • 2100_network_camera
  • 2420_network_camera