Cross-Site Scripting Vulnerabilities in Mobotix IP Network Cameras
CVE-2006-2490

Currently unrated

Key Information:

Vendor

Mobotix

Vendor
CVE Published:
19 May 2006

What is CVE-2006-2490?

Mobotix IP Network Cameras have multiple cross-site scripting vulnerabilities that allow remote attackers to inject arbitrary web scripts or HTML. These vulnerabilities exist due to improper validation of URL-encoded parameters, specifically in the query strings of certain actions, enabling attackers to exploit the devices through methods such as the 'help/help' query string and parameters like 'get_image_info_abspath' and 'source_ip'. Affected versions include M1 and M10 models prior to specified updates, posing a significant risk to the security of the networked video systems.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.