Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the conf_SMTP_MailServer1 parameter to ServerManager.srv and (2) a hostname change through the conf_Network_HostName parameter on the Network page.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www.procheckup.com/Vulnerability_Axis_2100_research.pdf | exploit |
http://osvdb.org/39490 | vdb entry |
http://securityreason.com/securityalert/3188 | third party advisory |
http://www.securityfocus.com/bid/25837 | vdb entry |
http://osvdb.org/39491 | vdb entry |
http://www.securityfocus.com/archive/1/480995/100/0/threaded | mailing list |