CVE-2019-13407
29.08.2019, 01:15
A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.
Vendor | Product | Version |
---|---|---|
androvideo | vd_1_firmware | 𝑥 ≤ 230 |
geovision | gv-vr360_firmware | 𝑥 ≤ 1.10 |
geovision | gv-vd8700_firmware | 𝑥 ≤ 1.01 |
𝑥
= Vulnerable software versions
References