Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)

Project Subscriptions

Vendors Products
Hanwha-security Subscribe
Hrd-1641 Subscribe
Hrd-1641 Firmware Subscribe
Hrd-1642 Subscribe
Hrd-1642 Firmware Subscribe
Hrd-440 Subscribe
Hrd-440 Firmware Subscribe
Hrd-442 Subscribe
Hrd-442 Firmware Subscribe
Hrd-443 Subscribe
Hrd-443 Firmware Subscribe
Hrd-840 Subscribe
Hrd-840 Firmware Subscribe
Hrd-841 Subscribe
Hrd-841 Firmware Subscribe
Hrd-842 Subscribe
Hrd-842 Firmware Subscribe
Srd-1694u Subscribe
Srd-1694u Firmware Subscribe
Samsung Subscribe
Smartviewer Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2018-3708 Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T08:17:08.457Z

Reserved: 2018-06-03T00:00:00.000Z

Link: CVE-2018-11689

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-14T20:29:00.317

Modified: 2024-11-21T03:43:49.723

Link: CVE-2018-11689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses