CVE-2007-4930

Axis 207w Network Camera - CSRF

Title source: rule

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform certain actions as administrators via (1) axis-cgi/admin/restart.cgi, (2) the user and sgrp parameters to axis-cgi/admin/pwdgrp.cgi in an add action, or (3) the server parameter to admin/restartMessage.shtml.

Exploits (3)

exploitdb WRITEUP VERIFIED
by Seth Fogie · textwebappscgi
https://www.exploit-db.com/exploits/30585
exploitdb WORKING POC VERIFIED
by Seth Fogie · textwebappscgi
https://www.exploit-db.com/exploits/30586
exploitdb WORKING POC VERIFIED
by Seth Fogie · textwebappscgi
https://www.exploit-db.com/exploits/30587

Scores

EPSS 0.0854
EPSS Percentile 92.3%

Classification

CWE
CWE-352
Status draft

Affected Products (1)

axis/207w_network_camera

Timeline

Published Sep 18, 2007
Tracked Since Feb 18, 2026