Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-2227. PoCs published by Seth Art.
AI-analyzed exploit summary This exploit leverages a security-bypass vulnerability in UniFi Video by sending a crafted POST request to create an admin user. It then exfiltrates the response to a malicious site, demonstrating unauthorized privilege escalation.
Description
The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.
Exploits (1)
This exploit leverages a security-bypass vulnerability in UniFi Video by sending a crafted POST request to create an admin user. It then exfiltrates the response to a malicious site, demonstrating unauthorized privilege escalation.