An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP Server mod_include module with "<!--#exec cmd=" support. The file needs to include a specific string to meet the internal system architecture. After the webshell upload, an attacker can use the webshell to perform remote code execution such as running a system command (ls, ping, cat /etc/passwd, etc.). NOTE: the vendor reportedly indicates that this is an intended feature or functionality
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.slideshare.net/secret/pRWQOOe6rN8Iyb |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T07:17:51.301Z
Reserved: 2018-03-31T00:00:00
Link: CVE-2018-9157
No data.
Status : Modified
Published: 2018-04-01T18:29:00.413
Modified: 2024-11-21T04:15:05.853
Link: CVE-2018-9157
No data.
OpenCVE Enrichment
No data.
Weaknesses