Record summary

CVE-2014-2227 has a selected CVSS score of 6.0; EIP currently links 1 catalogued exploit.

Description

The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBUbiquiti Networks UniFi Video Default - 'crossdomain.xml' Security BypassExploitDB exploitby Seth ArtNot analyzed1 file
ExploitDB

PoC details

References

4