[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Everfocus <= 1.4 EDSR Remote Authentication Bypass

Author
Andrea Fabrizi
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9896
Category
web applications
Date add
14-10-2009
Platform
unsorted
==================================================
Everfocus <= 1.4 EDSR Remote Authentication Bypass 
==================================================

**************************************************************
Product: Everfocus EDSR series
Version affected: 1.4 and older
Website: http://www.everfocus.com/
Discovered By: Andrea Fabrizi
Vuln: remote DVR applet authentication bypass
**************************************************************
 
The EDSR firmware don't handle correctly users authentication and sessions.
 
This exploit let you to connect to every remote DVR (without username
and password) and see the live cams :)
Exploit: http://www.inj3ct0r.com/sploits/9896.gz
 
I discovered this vulnerability one year ago and i have informed the
vendor, but apparently
there is no solution at this time.



#  0day.today [2024-09-28]  #