A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
androvideo vd_1_firmware |
||
geovision gv-vr360_firmware |
||
geovision gv-vd8700_firmware |