Axis StorPoint CD Authentication Vulnerability
BID:1025
Info
Axis StorPoint CD Authentication Vulnerability
| Bugtraq ID: | 1025 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 01 2000 12:00AM |
| Updated: | Mar 01 2000 12:00AM |
| Credit: | This bug was discovered by Infosec a Swedish based tigerteam and was posted to the Bugtraq mailing list on Tue Feb 29, 2000. |
| Vulnerable: |
Axis Communications StorPoint CD |
| Not Vulnerable: | |
Discussion
Axis StorPoint CD Authentication Vulnerability
Axis StorPoint CD and Axis StorPoint CD/T are CD ROM servers (actual hardware units)sold by Axis Communications. Both of these appliances support remote management
via SNMP MIB-II and private enterprise MIB as well as from the web via a system-supplied webserver. In regards to the web based administration, users can completely bypass authentication (username and password) by using a specified URL. The actual login page is located at:
http://server/config/html/cnf_gi.htm
However, by using:
http://server/cd/../config/html/cnf_gi.htm
A user side steps the login page and gains administrative access to the appliance.
Axis StorPoint CD and Axis StorPoint CD/T are CD ROM servers (actual hardware units)sold by Axis Communications. Both of these appliances support remote management
via SNMP MIB-II and private enterprise MIB as well as from the web via a system-supplied webserver. In regards to the web based administration, users can completely bypass authentication (username and password) by using a specified URL. The actual login page is located at:
http://server/config/html/cnf_gi.htm
However, by using:
http://server/cd/../config/html/cnf_gi.htm
A user side steps the login page and gains administrative access to the appliance.