漏洞信息详情
Axis Network Camera和Video Server多个漏洞
- CNNVD编号:CNNVD-200412-1131
- 危害等级: 高危
- CVE编号:
CVE-2004-2425
- 漏洞类型:
设计错误
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
axis - 漏洞来源:
bashis @wcd.se…
-
漏洞简介
Axis Network Camera 2.40及其早期版本和Video Server 3.12及其早期版本存在漏洞。远程攻击者借助virtualinput.cgi的查询字符串的重音(`)和可能其他shell元字符执行任意命令。
漏洞公告
Axis Communications has released upgrades to deal with this issue. Please see the referenced Bugtraq message for more information.
Axis Communications 2401 Video Server 1.0 1
Axis Communications Axis 2401 Video Server (2.34.1)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2401/sr/2_34_1/
Axis Communications 2400 Video Server 1.0 1
-
Axis Communications Axis 2400 Video Server (2.34.1)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400/sr/2_34_1/ -
Axis Communications Axis 2400+ Video Server (3.13)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400p/release_candidate/3_13/
Axis Communications 2400 Video Server 1.0 2
-
Axis Communications Axis 2400 Video Server (2.34.1)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400/sr/2_34_1/ -
Axis Communications Axis 2400+ Video Server (3.13)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400p/release_candidate/3_13/
Axis Communications 2400 Video Server 1.10
-
Axis Communications Axis 2400 Video Server (2.34.1)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400/sr/2_34_1/ -
Axis Communications Axis 2400+ Video Server (3.13)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400p/release_candidate/3_13/
Axis Communications 2400 Video Server 1.11
-
Axis Communications Axis 2400 Video Server (2.34.1)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400/sr/2_34_1/ -
Axis Communications Axis 2400+ Video Server (3.13)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400p/release_candidate/3_13/
Axis Communications 2400 Video Server 1.12
-
Axis Communications Axis 2400 Video Server (2.34.1)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400/sr/2_34_1/ -
Axis Communications Axis 2400+ Video Server (3.13)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400p/release_candidate/3_13/
Axis Communications 2400 Video Server 1.15
-
Axis Communications Axis 2400 Video Server (2.34.1)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400/sr/2_34_1/ -
Axis Communications Axis 2400+ Video Server (3.13)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400p/release_candidate/3_13/
Axis Communications 2401 Video Server 1.15
-
Axis Communications Axis 2401 Video Server (2.34.1)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2401/sr/2_34_1/
Axis Communications 2400 Video Server 2.0
-
Axis Communications Axis 2400 Video Server (2.34.1)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400/sr/2_34_1/ -
Axis Communications Axis 2400+ Video Server (3.13)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400p/release_candidate/3_13/
Axis Communications 2490 Serial Server 2.11.3
-
Axis Communications Axis 2490 Serial Server (2.12)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2490/release_candidate/3_13/
Axis Communications 2100 Network Camera 2.12
-
Axis Communications Axis 2100 Network Camera (2.42)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2100/release_candidate/2_42/
Axis Communications 2420 Network Camera 2.12
-
Axis Communications Axis 2420 Network Camera (2.42)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2420/release_candidate/2_42/
Axis Communications 2120 Network Camera 2.12
-
Axis Communications Axis 2120 Network Camera (2.42)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2120/release_candidate/2_42/
Axis Communications 2110 Network Camera 2.12
-
Axis Communications Axis 2110 Network Camera (2.42)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2110/release_candidate/2_42/
Axis Communications 2400 Video Server 2.20
-
Axis Communications Axis 2400 Video Server (2.34.1)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400/sr/2_34_1/ -
Axis Communications Axis 2400+ Video Server (3.13)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400p/release_candidate/3_13/
Axis Communications 2401 Video Server 2.20
-
Axis Communications Axis 2401 Video Server (2.34.1)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2401/sr/2_34_1/
Axis Communications 2420 Network Camera 2.30
-
Axis Communications Axis 2420 Network Camera (2.42)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2420/release_candidate/2_42/
Axis Communications 2110 Network Camera 2.30
-
Axis Communications Axis 2110 Network Camera (2.42)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2110/release_candidate/2_42/
Axis Communications 2100 Network Camera 2.30
-
Axis Communications Axis 2100 Network Camera (2.42)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2100/release_candidate/2_42/
Axis Communications 2401 Video Server 2.30
-
Axis Communications Axis 2401 Video Server (2.34.1)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2401/sr/2_34_1/
Axis Communications 2400 Video Server 2.30
-
Axis Communications Axis 2400 Video Server (2.34.1)
ftp://ftp.axis.com/pub_soft/cam_srv/cam_2400/sr/2_34_1/ -
Axis Communications Axis 2400+ Video Server (3.13)
参考网址
来源: BID
名称: 11011
链接:http://www.securityfocus.com/bid/11011
来源: SECTRACK
名称: 1011056
链接:http://securitytracker.com/id?1011056
来源: SECUNIA
名称: 12353
链接:http://secunia.com/advisories/12353
来源: FULLDISC
名称: 20040831 Axis Network Camera and Video Server Security Advisory
链接:http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1282.html
来源: XF
名称: asix-command-execution(17076)
链接:http://xforce.iss.net/xforce/xfdb/17076
来源: OSVDB
名称: 9121
链接:http://www.osvdb.org/9121
来源: FULLDISC
名称: 20040822 [PoC] Nasty bug(s) found in Axis Network Camera/Video Servers
链接:http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0948.html