CVE-2006-2490

Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before 2.2.3.18 for M10/D10 and 3.0.3.31 for M22, allow remote attackers to inject arbitrary web script or HTML via URL-encoded values in (1) the query string to help/help, (2) the get_image_info_abspath parameter to control/eventplayer, and (3) the source_ip parameter to events.tar.

BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/434289/100/0/threaded
BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/444018/100/0/threaded
MISC: http://www.eazel.es/media/advisory001.html
VIM: http://www.attrition.org/pipermail/vim/2006-August/000980.html
BID: http://www.securityfocus.com/bid/18022
VUPEN: http://www.vupen.com/english/advisories/2006/1857
OSVDB: http://www.osvdb.org/25621
OSVDB: http://www.osvdb.org/25622
OSVDB: http://www.osvdb.org/25623
SECTRACK: http://securitytracker.com/id?1016128
SECUNIA: http://secunia.com/advisories/20151
SREASON: http://securityreason.com/securityalert/929
XF: http://xforce.iss.net/xforce/xfdb/26538
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2490

14 years
256 countries
683k users
4525k calculations
Logo www.systemy-stech.cz
Logo sectech.co.nz
Logo www.use-ip.co.uk
Logo www.power-shop.gr
Logo www.eleksys.cz
Logo reolink.com