4.3
CVSSv2

CVE-2009-1557

Published: 06/05/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allow remote malicious users to inject arbitrary web script or HTML via the next_file parameter to (1) main.cgi, (2) img/main.cgi, or (3) adm/file.cgi; or (4) the this_file parameter to adm/file.cgi.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco wvc54gca 1.00r24

cisco wvc54gca 1.00r22

Exploits

source: wwwsecurityfocuscom/bid/34714/info Linksys WVC54GCA Wireless-G Internet Home Monitoring Camera is prone to multiple cross-site scripting vulnerabilities because the software fails to sufficiently sanitize user-supplied data An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting u ...