CVE-2007-5212
Last modified
CVE-2007-5212 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware before 2.43 allow remote attackers to inject arbitrary web script or HTML via (1) parameters associated with saved settings, as demonstrated by the conf_SMTP_MailServer1 parameter to ServerManager.srv; or (2) the subpage parameter to wizard/first/wizard_main_first.shtml. NOTE: an attacker can leverage a CSRF vulnerability to modify saved settings.. EPSS estimates a 1.94% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware before 2.43 allow remote attackers to inject arbitrary web script or HTML via (1) parameters associated with saved settings, as demonstrated by the conf_SMTP_MailServer1 parameter to ServerManager.srv; or (2) the subpage parameter to wizard/first/wizard_main_first.shtml. NOTE: an attacker can leverage a CSRF vulnerability to modify saved settings.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Axis | 2100 Network Camera | 2.02 |
| Axis | 2100 Network Camera Firmware | <= 2.42 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5212?
How severe is CVE-2007-5212?
How do I fix CVE-2007-5212?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5201The FTP backend for Duplicity before 0.4.9 sends the passwor…
- CVE-2007-5207guilt 0.27 allows local users to overwrite arbitrary files v…
- CVE-2007-5208hpssd in Hewlett-Packard Linux Imaging and Printing Project …
- CVE-2007-5209Stack-based buffer overflow in DriveLock.exe in CenterTools …
- CVE-2007-5210Arbor Networks Peakflow SP before 3.5.1 patch 14, and 3.6.x …
- CVE-2007-5211Multiple cross-site scripting (XSS) vulnerabilities in Arbor…
- CVE-2007-5213Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2007-5214Multiple cross-site scripting (XSS) vulnerabilities in the A…
- CVE-2007-5215Multiple PHP remote file inclusion vulnerabilities in Jacob …
- CVE-2007-5216Multiple PHP remote file inclusion vulnerabilities in eArk (…
- CVE-2007-5217Stack-based buffer overflow in the ADM4 ActiveX control in a…
- CVE-2007-5218Cross-site scripting (XSS) vulnerability in index.php in Don…
Are you affected by CVE-2007-5212?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
