Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-2490
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-2490

Description:
Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before 2.2.3.18 for M10/D10 and 3.0.3.31 for M22, allow remote attackers to inject arbitrary web script or HTML via URL-encoded values in (1) the query string to help/help, (2) the get_image_info_abspath parameter to control/eventplayer, and (3) the source_ip parameter to events.tar.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/26538

VIM
  http://www.attrition.org/pipermail/vim/2006-August/000980.html

ST
  1016128

SREASON
  http://securityreason.com/securityalert/929

SAID
  Secunia Advisory: SA20151

OSVDB
  25622
  25621
  25623

MISC
  http://www.eazel.es/media/advisory001.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/444018/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/434289/100/0/threaded

BID
  18022


Return to the previous page.