First published: Thu Jan 03 2019(Updated: )
Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vivotek Camera |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-18244.
The severity of CVE-2018-18244 is medium (6.1).
The affected software is VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x.
The impact of CVE-2018-18244 is that remote attackers can execute arbitrary JavaScript code via an HTTP Referer Header.
Yes, you can find references for CVE-2018-18244 at the following links: [http://download.vivotek.com/downloadfile/support/cyber-security/vvtk-sa-2018-006-v1.pdf](http://download.vivotek.com/downloadfile/support/cyber-security/vvtk-sa-2018-006-v1.pdf), [https://blog.securityevaluators.com/vivotek-ip-camera-vulnerabilities-discovered-and-exploited-2e2531ecd244](https://blog.securityevaluators.com/vivotek-ip-camera-vulnerabilities-discovered-and-exploited-2e2531ecd244)