CVE-2018-11689

Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
References
Link Resource
https://vulmon.com/vulnerabilitydetails?qid=CVE-2018-11689 Third Party Advisory
http://www.securityfocus.com/archive/1/542083/100/0/threaded Exploit Third Party Advisory URL Repurposed VDB Entry
https://seclists.org/bugtraq/2018/Jun/40 Exploit Mailing List Third Party Advisory
https://drive.google.com/file/d/1aWbvdrx1KRkUv4ikkm530a2N5qrxCLmr/view?usp=sharing Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:samsung:smartviewer:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-1642_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-1642:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-842_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-842:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-442_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-442:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-1641_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-1641:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-841_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-841:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-840:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-440_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-440:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-443_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-443:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:hanwha-security:srd-1694u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:srd-1694u:-:*:*:*:*:*:*:*

Information

Published : 2018-06-14 13:29

Updated : 2022-04-23 18:54


NVD link : CVE-2018-11689

Mitre link : CVE-2018-11689


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

hanwha-security

  • hrd-1642_firmware
  • hrd-443
  • hrd-443_firmware
  • hrd-442
  • hrd-440
  • hrd-842_firmware
  • srd-1694u_firmware
  • srd-1694u
  • hrd-841_firmware
  • hrd-442_firmware
  • hrd-840
  • hrd-440_firmware
  • hrd-841
  • hrd-1641_firmware
  • hrd-840_firmware
  • hrd-842
  • hrd-1642
  • hrd-1641

samsung

  • smartviewer