ID

VAR-200709-0163


CVE

CVE-2007-4929


TITLE

AXIS Cross-site scripting vulnerability in cameras

Trust: 0.8

sources: JVNDB: JVNDB-2007-002642

DESCRIPTION

Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 207W camera allow remote attackers to inject arbitrary web script or HTML via the camNo parameter to incl/image_incl.shtml, and other unspecified vectors. 207W Network Camera is prone to a cross-site scripting vulnerability. AXIS 207W is a network camera that provides wireless IEEE802.11g and Ethernet interfaces. ---------------------------------------------------------------------- BETA test the new Secunia Personal Software Inspector! The Secunia PSI detects installed software on your computer and categorises it as either Insecure, End-of-Life, or Up-To-Date. Effectively enabling you to focus your attention on software installations where more secure versions are available from the vendors. Download the free PSI BETA from the Secunia website: https://psi.secunia.com/ ---------------------------------------------------------------------- TITLE: AXIS 207W Network Camera Multiple Vulnerabilities SECUNIA ADVISORY ID: SA26831 VERIFY ADVISORY: http://secunia.com/advisories/26831/ CRITICAL: Less critical IMPACT: Cross Site Scripting, DoS WHERE: >From remote OPERATING SYSTEM: Axis Network Camera http://secunia.com/product/908/ DESCRIPTION: Seth Fogie has reported some vulnerabilities in the AXIS 207W Network Camera, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks, or by malicious users to cause a DoS (Denial of Service). 1) Input passed to the "camNo" parameter in incl/image_incl.shtml is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. 2) The web interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited to e.g. reboot the camera, add a new administrator, or to install a backdoor by enticing a logged-in administrator to visit a malicious site. 3) An unspecified vulnerability exists within the axis-cgi/buffer/command.cgi script. This can be exploited to reboot the vulnerable system by issuing multiple HTTP requests (more than 129) for the affected script with the "do" parameter set to "start" and with an arbitrary value for the "buffername" parameter. Successful exploitation of this vulnerability requires valid user credentials. SOLUTION: Filter traffic to affected devices and do not visit untrusted web sites while being logged in to the device. PROVIDED AND/OR DISCOVERED BY: Seth Fogie, Airscanner Mobile Security ORIGINAL ADVISORY: http://airscanner.com/security/07080701_axis.htm OTHER REFERENCES: http://www.informit.com/articles/article.aspx?p=1016102 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 2.07

sources: NVD: CVE-2007-4929 // JVNDB: JVNDB-2007-002642 // BID: 81560 // VULHUB: VHN-28291 // PACKETSTORM: 59326

IOT TAXONOMY

category:['camera device']sub_category:camera

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:axismodel:207w network camerascope: - version: -

Trust: 1.4

vendor:axismodel:207w network camerascope:eqversion:*

Trust: 1.0

vendor:axismodel:communications 207w network camerascope:eqversion:0

Trust: 0.3

sources: BID: 81560 // JVNDB: JVNDB-2007-002642 // CNNVD: CNNVD-200709-237 // NVD: CVE-2007-4929

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-4929
value: MEDIUM

Trust: 1.0

NVD: CVE-2007-4929
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200709-237
value: MEDIUM

Trust: 0.6

VULHUB: VHN-28291
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2007-4929
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-28291
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-28291 // JVNDB: JVNDB-2007-002642 // CNNVD: CNNVD-200709-237 // NVD: CVE-2007-4929

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-28291 // JVNDB: JVNDB-2007-002642 // NVD: CVE-2007-4929

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200709-237

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-200709-237

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-002642

PATCH

title:Top Pageurl:http://www.axis.com/techsup/software/acc/index.htm

Trust: 0.8

sources: JVNDB: JVNDB-2007-002642

EXTERNAL IDS

db:NVDid:CVE-2007-4929

Trust: 2.9

db:SECTRACKid:1018699

Trust: 2.0

db:BIDid:25678

Trust: 2.0

db:SREASONid:3145

Trust: 2.0

db:SECUNIAid:26831

Trust: 1.8

db:JVNDBid:JVNDB-2007-002642

Trust: 0.8

db:BUGTRAQid:20070915 AXIS 207W WIRELESS CAMERA WEB INTERFACE - MULTIPLE VULNERABILITIES

Trust: 0.6

db:CNNVDid:CNNVD-200709-237

Trust: 0.6

db:BIDid:81560

Trust: 0.4

db:OTHERid:NONE

Trust: 0.1

db:VULHUBid:VHN-28291

Trust: 0.1

db:PACKETSTORMid:59326

Trust: 0.1

sources: OTHER: None // VULHUB: VHN-28291 // BID: 81560 // JVNDB: JVNDB-2007-002642 // PACKETSTORM: 59326 // CNNVD: CNNVD-200709-237 // NVD: CVE-2007-4929

REFERENCES

url:http://airscanner.com/security/07080701_axis.htm

Trust: 2.1

url:http://www.informit.com/articles/article.aspx?p=1016102

Trust: 2.1

url:http://www.securityfocus.com/bid/25678

Trust: 2.0

url:http://www.securitytracker.com/id?1018699

Trust: 2.0

url:http://securityreason.com/securityalert/3145

Trust: 2.0

url:http://secunia.com/advisories/26831

Trust: 1.7

url:http://www.securityfocus.com/archive/1/479600/100/0/threaded

Trust: 1.1

url:http://www.securityfocus.com/archive/1/archive/1/479600/100/0/threaded

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-4929

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-4929

Trust: 0.8

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

url:http://secunia.com/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/about_secunia_advisories/

Trust: 0.1

url:https://psi.secunia.com/

Trust: 0.1

url:http://secunia.com/product/908/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/26831/

Trust: 0.1

sources: OTHER: None // VULHUB: VHN-28291 // BID: 81560 // JVNDB: JVNDB-2007-002642 // PACKETSTORM: 59326 // CNNVD: CNNVD-200709-237 // NVD: CVE-2007-4929

CREDITS

Seth Fogie※ contact@airscanner.com

Trust: 0.6

sources: CNNVD: CNNVD-200709-237

SOURCES

db:OTHERid: -
db:VULHUBid:VHN-28291
db:BIDid:81560
db:JVNDBid:JVNDB-2007-002642
db:PACKETSTORMid:59326
db:CNNVDid:CNNVD-200709-237
db:NVDid:CVE-2007-4929

LAST UPDATE DATE

2025-04-10T20:53:09.785000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-28291date:2018-10-15T00:00:00
db:BIDid:81560date:2007-09-18T00:00:00
db:JVNDBid:JVNDB-2007-002642date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200709-237date:2007-10-08T00:00:00
db:NVDid:CVE-2007-4929date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-28291date:2007-09-18T00:00:00
db:BIDid:81560date:2007-09-18T00:00:00
db:JVNDBid:JVNDB-2007-002642date:2012-06-26T00:00:00
db:PACKETSTORMid:59326date:2007-09-18T14:57:18
db:CNNVDid:CNNVD-200709-237date:2007-09-18T00:00:00
db:NVDid:CVE-2007-4929date:2007-09-18T18:17:00