First published: Wed Oct 25 2017(Updated: )
Reflected XSS in the web administration portal on the Axis 2100 Network Camera 2.03 allows an attacker to execute arbitrary JavaScript via the conf_Layout_OwnTitle parameter to view/view.shtml. NOTE: this might overlap CVE-2007-5214.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Axis 2100 Network Camera Firmware | =2.03 | |
Axis 2100 Network Camera Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15885 is considered a medium severity vulnerability due to its potential for reflected XSS attacks.
To fix CVE-2017-15885, it is recommended to upgrade the Axis 2100 Network Camera firmware to a version that addresses the XSS vulnerability.
CVE-2017-15885 can facilitate reflected cross-site scripting (XSS) attacks, allowing an attacker to execute arbitrary JavaScript.
CVE-2017-15885 affects the Axis 2100 Network Camera running firmware version 2.03.
Yes, CVE-2017-15885 may overlap with CVE-2007-5214, indicating potential similarities in the vulnerabilities.