PT-2017-14263 · Axis · Axis 2100 Network Camera

Publicado

2017-10-25

·

Atualizado

2017-11-14

·

CVE-2017-15885

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Axis 2100 Network Camera version 2.03
Description The issue concerns a Reflected XSS in the web administration portal. An attacker can execute arbitrary JavaScript via the conf Layout OwnTitle parameter to the "view/view.shtml" endpoint.
Recommendations For Axis 2100 Network Camera version 2.03, avoid using the conf Layout OwnTitle parameter in the "view/view.shtml" endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the web administration portal to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-15885

Produtos afetados

Axis 2100 Network Camera