PT-2019-9543 · Vivotek · Vivotek Network Camera Series

Publicado

2019-01-03

·

Atualizado

2019-01-14

·

CVE-2018-18005

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions VIVOTEK Network Camera Series products with firmware 0x06x through 0x08x
Description The issue concerns cross-site scripting in the event script.js file, allowing remote attackers to execute arbitrary JavaScript code via a URL query string parameter.
Recommendations For VIVOTEK Network Camera Series products with firmware 0x06x through 0x08x, update the firmware to a version that is not affected by this issue.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18005

Produtos afetados

Vivotek Network Camera Series