CVE-2018-18244: XSS
Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-18244.
What is the severity of CVE-2018-18244?
The severity of CVE-2018-18244 is medium (6.1).
What is the affected software?
The affected software is VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x.
What is the impact of CVE-2018-18244?
The impact of CVE-2018-18244 is that remote attackers can execute arbitrary JavaScript code via an HTTP Referer Header.
Are there any references for CVE-2018-18244?
Yes, you can find references for CVE-2018-18244 at the following links: [http://download.vivotek.com/downloadfile/support/cyber-security/vvtk-sa-2018-006-v1.pdf](http://download.vivotek.com/downloadfile/support/cyber-security/vvtk-sa-2018-006-v1.pdf), [https://blog.securityevaluators.com/vivotek-ip-camera-vulnerabilities-discovered-and-exploited-2e2531ecd244](https://blog.securityevaluators.com/vivotek-ip-camera-vulnerabilities-discovered-and-exploited-2e2531ecd244)