header-logo
Suggest Exploit
vendor:
Network Camera
by:
Orwelllabs
6,1
CVSS
MEDIUM
Improper Input Validation
20
CWE
Product Name: Network Camera
Affected Version From: 0.0
Affected Version To: 0.0
Patch Exists: Yes
Related CWE: CVE-2015-8256
CPE: a:axis:network_camera
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2016

Axis Network Cameras Multiple Cross-site scripting

Axis Network Cameras are prone to multiple (stored/reflected) cross-site scripting vulnerability. Attack vectors allow you to execute an arbitrary javascript code in the user browser (session) with this steps: Attacker injects a javascript payload in the vulnerable page: http://{axishost}/axis-cgi/vaconfig.cgi?action=get&name=<script type="text/javascript>prompt("AXIS_PASSWORD:")</script> This will create a entry in the genneral log file (/var/log/messages) So, when the user is viewing the log 'system options' -> 'support' -> 'Logs & Reports': http://{axishost}/axis-cgi/admin/systemlog.cgi?id will be displayed a prompt for the password of the current user ('AXIS_PASSWORD'). However, due to CSRF presented is even possible to perfor the attack without the user interaction.

Mitigation:

Axis Communications recommends that users upgrade to the latest version of the firmware.
Source

Exploit-DB raw data: