CVE-2007-4930
published 2007-09-18CVE-2007-4930: Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform certain actions as administrators via (1)…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
2.18%
80.1th percentile
Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform certain actions as administrators via (1) axis-cgi/admin/restart.cgi, (2) the user and sgrp parameters to axis-cgi/admin/pwdgrp.cgi in an add action, or (3) the server parameter to admin/restartMessage.shtml.
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Axis Communications 207W Network Camera - Web Interface axis-cgi/admin/restart.cgi Cross-Site Request Forgery
exploitdb·2007-09-14
CVE-2007-4930 Axis Communications 207W Network Camera - Web Interface axis-cgi/admin/restart.cgi Cross-Site Request Forgery
Axis Communications 207W Network Camera - Web Interface axis-cgi/admin/restart.cgi Cross-Site Request Forgery
---
source: https://www.securityfocus.com/bid/25678/info
Axis Communications 207W Network Camera is prone to multiple vulnerabilities in the web interface. Three issues were reported: a cross-site scripting vulnerability, a cross-site request-forgery vulnerability, and a denial-of-service vulnerability.
Exploiting these issues may allow an attacker to compromise the device or to prevent other users from using the device.
Reboot the camera - http://www.example.com/axis-cgi/admin/restart.cgi
Exploit-DB
Axis Communications 207W Network Camera - Web Interface 'axis-cgi/admin/pwdgrp.cgi' Multiple Cross-Site Request Forgery Vulnerabilities
exploitdb·2007-09-14
CVE-2007-4930 Axis Communications 207W Network Camera - Web Interface 'axis-cgi/admin/pwdgrp.cgi' Multiple Cross-Site Request Forgery Vulnerabilities
Axis Communications 207W Network Camera - Web Interface 'axis-cgi/admin/pwdgrp.cgi' Multiple Cross-Site Request Forgery Vulnerabilities
---
source: https://www.securityfocus.com/bid/25678/info
Axis Communications 207W Network Camera is prone to multiple vulnerabilities in the web interface. Three issues were reported: a cross-site scripting vulnerability, a cross-site request-forgery vulnerability, and a denial-of-service vulnerability.
Exploiting these issues may allow an attacker to compromise the device or to prevent other users from using the device.
Add a new administrator -
http://www.example.com/axis-cgi/admin/pwdgrp.cgi?action=add&user=owner1&grp=axuser&sgrp=axview:axoper:axadmin&pwd=owner1&comment=WebUser&return_page=/admin/users_set.sh
+tml%3Fpageclose%3D1
Exploit-DB
Axis Communications 207W Network Camera - Web Interface '/admin/restartMessage.shtml?server' Cross-Site Request Forgery
exploitdb·2007-09-14
CVE-2007-4930 Axis Communications 207W Network Camera - Web Interface '/admin/restartMessage.shtml?server' Cross-Site Request Forgery
Axis Communications 207W Network Camera - Web Interface '/admin/restartMessage.shtml?server' Cross-Site Request Forgery
---
source: https://www.securityfocus.com/bid/25678/info
Axis Communications 207W Network Camera is prone to multiple vulnerabilities in the web interface. Three issues were reported: a cross-site scripting vulnerability, a cross-site request-forgery vulnerability, and a denial-of-service vulnerability.
Exploiting these issues may allow an attacker to compromise the device or to prevent other users from using the device.
Root the camera/add a backdoor -
http://www.example.com/admin/restartMessage.shtml?server=<!â??
No writeups or analysis indexed.
http://airscanner.com/security/07080701_axis.htmhttp://secunia.com/advisories/26831http://securityreason.com/securityalert/3145http://www.informit.com/articles/article.aspx?p=1016102http://www.securityfocus.com/archive/1/479600/100/0/threadedhttp://www.securityfocus.com/bid/25678http://www.securitytracker.com/id?1018699http://airscanner.com/security/07080701_axis.htmhttp://secunia.com/advisories/26831http://securityreason.com/securityalert/3145http://www.informit.com/articles/article.aspx?p=1016102http://www.securityfocus.com/archive/1/479600/100/0/threadedhttp://www.securityfocus.com/bid/25678http://www.securitytracker.com/id?1018699
2007-09-18
Published