Cross-Site Scripting Vulnerabilities in Cisco Linksys Wireless Video Camera
CVE-2009-1557
Currently unrated
Summary
The Cisco Linksys WVC54GCA wireless video camera is susceptible to multiple cross-site scripting (XSS) vulnerabilities. These flaws arise from improper handling of user-supplied input in the next_file parameter for various CGI scripts, including main.cgi, img/main.cgi, and adm/file.cgi. Attackers can exploit these vulnerabilities to inject arbitrary web script or HTML, potentially allowing them to execute malicious actions in the context of an unsuspecting user's session.
References
EPSS Score
6% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved