- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 19784
- Проверка EDB
-
- Пройдено
- Автор
- INFOSEC SWEDISH BASED TIGERTEAM
- Тип уязвимости
- REMOTE
- Платформа
- MULTIPLE
- CVE
- cve-2000-0191
- Дата публикации
- 2000-03-01
Axis Communications StorPoint CD - Authentication Bypass
Код:
source: https://www.securityfocus.com/bid/1025/info
Axis StorPoint CD and Axis StorPoint CD/T are CD ROM servers (actual hardware units)sold by Axis Communications. Both of these appliances support remote management
via SNMP MIB-II and private enterprise MIB as well as from the web via a system-supplied webserver. In regards to the web based administration, users can completely bypass authentication (username and password) by using a specified URL. The actual login page is located at:
http://server/config/html/cnf_gi.htm
However, by using:
http://server/cd/../config/html/cnf_gi.htm
A user side steps the login page and gains administrative access to the appliance.
http://server/cd/../config/html/cnf_gi.htm
- Источник
- www.exploit-db.com