|
Axis Network Camera and Video Server contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the virtualinput.cgi script not requiring authentication and not properly sanitizing user supplied input. By sending a specially crafted URL, an attacker can use this script to inject arbitrary commands which will be executed by the server.
|