Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

webcamXP < 2.16.478 Chat Name HTML Injection

Medium

Synopsis

The remote host is vulnerable to an HTML Injection attack.

Description

The remote host is running the webcamXP application. webcamXP is an all-in-one camera/webserver appliance that allows users to view and administer a camera remotely. This version of webcamXP is vulnerable to an HTML injection flaw. An attacker exploiting this flaw would typically need to be able to entice a user into browsing to a malicious URI. Successful exploitation would result in the theft of confidential materials (such as authentication cookies).

Solution

Upgrade to version 2.16.478 or higher.