CVE-2018-18244

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
03/01/2019
Last modified:
14/01/2019

Description

Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:vivotek:camera:-:*:*:*:*:*:*:*