PT-2003-2112 · Unknown · Flexwatch Network Video Server
Published
2003-10-30
·
Updated
2017-07-11
·
CVE-2003-1160
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FlexWATCH Network video server version 132
Description
The issue allows remote attackers to bypass authentication and gain administrative privileges. This can be achieved by sending an HTTP request to the "aindex.htm" endpoint that contains double leading slashes (//).
Recommendations
For FlexWATCH Network video server version 132, consider restricting access to the "aindex.htm" endpoint until a patch is available. As a temporary workaround, avoid using double leading slashes (//) in HTTP requests to prevent potential exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flexwatch Network Video Server