CVE-2021-47729
EUVD-2021-3474109.12.2025, 21:15
Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| selea | izero_box_full_firmware | - |
| selea | izero_column_entry\/8_firmware | - |
| selea | izero_column_full\/8_firmware | - |
| selea | targa_504_firmware | - |
| selea | targa_512_firmware | - |
| selea | targa_704_ilb_firmware | - |
| selea | targa_704_tkm_firmware | - |
| selea | targa_710_inox_firmware | - |
| selea | targa_750_firmware | - |
| selea | targa_805_firmware | - |
| selea | targa_semplice_firmware | - |
| selea | carplateserver | 3.005\(191112\) |
| selea | carplateserver | 3.005\(191206\) |
| selea | carplateserver | 3.100\(200225\) |
| selea | carplateserver | 4.013\(201105\) |
𝑥
= Vulnerable software versions