Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.
                
            References
                    | Link | Resource | 
|---|---|
| http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0948.html | Exploit | 
| http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1282.html | Patch Vendor Advisory | 
| http://secunia.com/advisories/12353 | Patch Vendor Advisory | 
| http://securitytracker.com/id?1011056 | Exploit Patch | 
| http://www.osvdb.org/9121 | |
| http://www.securityfocus.com/bid/11011 | Patch | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/17076 | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2004-12-31 05:00
Updated : 2017-07-11 01:31
NVD link : CVE-2004-2425
Mitre link : CVE-2004-2425
CVE.ORG link : CVE-2004-2425
JSON object : View
Products Affected
                axis
- 2130_ptz_network_camera
 - 230_mpeg2_video_server
 - 2420_network_camera
 - storpoint_cd
 - 2120_network_camera
 - 2460_network_dvr
 - 2110_network_camera
 - 250s_video_server
 - 2400_video_server
 - 2490_serial_server
 - 2401_video_server
 - 2420_video_server
 - 2100_network_camera
 - 2411_video_server
 
CWE
                