mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-14 19:18:06 +02:00
19 lines
940 B
Markdown
19 lines
940 B
Markdown
### [CVE-2014-1201](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1201)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 series with firmware 11.17.38-33_1D97A, and Edge3 LH340 series with firmware 11.19.85_1FE3A allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the HTTP_PORT parameter.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/pedrib/PoC/blob/master/lorexActivex/lorex-report.txt
|
|
- https://github.com/pedrib/PoC/blob/master/lorexActivex/lorex-testcase.html
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|