Cross-Site Scripting Vulnerabilities in Mobotix IP Network Cameras
CVE-2006-2490
Currently unrated
What is CVE-2006-2490?
Mobotix IP Network Cameras have multiple cross-site scripting vulnerabilities that allow remote attackers to inject arbitrary web scripts or HTML. These vulnerabilities exist due to improper validation of URL-encoded parameters, specifically in the query strings of certain actions, enabling attackers to exploit the devices through methods such as the 'help/help' query string and parameters like 'get_image_info_abspath' and 'source_ip'. Affected versions include M1 and M10 models prior to specified updates, posing a significant risk to the security of the networked video systems.
References
Timeline
Vulnerability published
Vulnerability Reserved