header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

GeoVision GV-ASManager 6.1.1.0 – CSRF

A CSRF vulnerability exists in GeoVision GV-ASManager web application version 6.1.1.0 or earlier, enabling attackers to create Admin accounts via a crafted GET request. This exploit is often combined with CVE-2024-56903 for a successful CSRF attack.

Information Disclosure in GeoVision GV-ASManager

An information disclosure vulnerability has been found in the GeoVision GV-ASManager web application with version 6.1.0.0 or lower. This vulnerability allows unauthorized access to sensitive information within the application, such as user accounts and clear text passwords, potentially leading to unauthorized access to monitoring cameras, access cards, and other critical data.

Broken Access Control in GeoVision GV-ASManager

The vulnerability exists in GeoVision GV-ASManager web application version 6.1.0.0 or below. An attacker with network access and a low privilege account can perform unauthorized actions like enabling/disabling accounts, creating new accounts, modifying privileges, and accessing resources. After privilege escalation, the attacker can access monitoring cameras, employee information, change configurations, disrupt services, clone access control data, and retrieve cleartext passwords for further attacks.

GeoVision GeoHttpServer WebCams Remote File Disclosure Exploit

The GeoVision GeoHttpServer application is prone to a remote file disclosure vulnerability. An attacker can exploit this vulnerability to retrieve and download stored files on server such as 'boot.ini' and 'win.ini' by using a simple url request which made by browser.

GeoVision LiveX_v8200 ActiveX Control (LIVEX_~1.OCX) remote file corruption poc

This proof-of-concept (PoC) code connects to a live demo server and replaces system.ini with jpeg content. It is working against IE8b/xpsp3, safe for scripting and for initialization. LiveX_v7000 and LiveX_v8120 with clsids {DA8484DE-52DB-4860-A986-61A8682E298A} and {F4421170-DB22-4551-BBFB-FFCFFB419F6F} have the same SnapShotToFile() and SnapShotX() methods.

Directory traversal vulnerability in Geovision Digital Video Surveillance System (geohttpserver)

A directory traversal vulnerability exists in Geovision Digital Video Surveillance System (geohttpserver) version 8.2, which allows an attacker to access arbitrary files on the system. This is achieved by sending a specially crafted HTTP request containing directory traversal sequences such as '../' to the vulnerable server.

GeoVision Geowebserver 5.3.3 – LFI / XSS / HHI / RCE

GeoVision Geowebserver 5.3.3 are vulnerable to several XSS / HTML Injection / Local File Include / XML Injection / Code execution vectors. The application fails to properly sanitize user requests. This allows injection of HTML code and XSS / client side exploitation, including session theft. Additionally, the vendor has issued an ineffective / broken patch which does not appear to remediate or address the problem. Versions 5.3.3 and below continue to be affected. This is acknowledged by the vendor. The devices are vulnerable to HOST HEADER POISONING and CROSS-SITE REQUEST FORGERY against the web application. These can be used for various vecors, including session hijacking.

Recent Exploits: