Full title: Schneider Electric Pelco Sarix/Spectra Cameras CSRF Enable SSH Root Access Vulnerability Category: web applications Platform: hardware Pelco IP cameras suffer from a cross site request forgery vulnerability. The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site. # 0day.today @ http://0day.today/