Record summary

CVE-2007-4930 has a selected CVSS score of 4.3; EIP currently links 3 catalogued exploits.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform certain actions as administrators via (1) axis-cgi/admin/restart.cgi, (2) the user and sgrp parameters to axis-cgi/admin/pwdgrp.cgi in an add action, or (3) the server parameter to admin/restartMessage.shtml.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
3

Proofs of concept

3

Catalogued exploits

ExploitDBAxis Communications 207W Network Camera - Web Interface axis-cgi/admin/restart.cgi Cross-Site Request ForgeryExploitDB exploitby Seth FogieNot analyzed1 file
ExploitDB

PoC details
ExploitDBAxis Communications 207W Network Camera - Web Interface 'axis-cgi/admin/pwdgrp.cgi' Multiple Cross-Site Request Forgery VulnerabilitiesExploitDB exploitby Seth FogieNot analyzed1 file
ExploitDB

PoC details
ExploitDBAxis Communications 207W Network Camera - Web Interface '/admin/restartMessage.shtml?server' Cross-Site Request ForgeryExploitDB exploitby Seth FogieNot analyzed1 file
ExploitDB

PoC details

References

8