vendor:
70U Network Document Server
by:
Digital Security Research Group [DSecRG]
4.3
CVSS
MEDIUM
Local File Include and Privilege Escalation, Multiple Linked XSS
94, 79
CWE
Product Name: 70U Network Document Server
Affected Version From: 3
Affected Version To: 3
Patch Exists: NO
Related CWE: N/A
CPE: h:axis:70u_network_document_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
AXIS 70U Network Document Server – Privilege Escalation and XSS
Local File Include vulnerability found in script user/help/help.shtml. User can unclude any local files even in admin folder. Linked XSS vulnerability found in scripts: user/help/help.shtml, user/help/general_help_user.shtml. Attacker can inject XSS script in URL.
Mitigation:
Vendor decided that this vulnerability is not critical and there is no patches for this firmware.