Files
CVEs-PoC/2017/CVE-2017-15885.md
T
2025-09-29 21:09:30 +02:00

18 lines
757 B
Markdown

### [CVE-2017-15885](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15885)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen)
### Description
Reflected XSS in the web administration portal on the Axis 2100 Network Camera 2.03 allows an attacker to execute arbitrary JavaScript via the conf_Layout_OwnTitle parameter to view/view.shtml. NOTE: this might overlap CVE-2007-5214.
### POC
#### Reference
- https://distributedcompute.com/2017/10/24/axis-2100-network-camera-2-03-xss-vulnerability/
#### Github
No PoCs found on GitHub currently.