Description
Multiple cross-site scripting (XSS) vulnerabilities in Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam Original Range YCB001, YCW001, running firmware 4.30 and earlier, allow remote authenticated users to inject arbitrary web script or HTML via the (1) SYSCONTACT parameter to form/identityApply, as triggered using en/identity.asp; (2) PASSWD parameter to form/accAdd, as triggered using en/account/accedit.asp; (3) NTPSERVER parameter to form/clockApply, as triggered using en/clock.asp; (4) SERVER parameter to form/smtpclientApply, as triggered using en/smtpclient.asp; (5) SERVER parameter to form/ftpApply, as triggered using en/ftp.asp; or (6) SERVER parameter to form/httpEventApply, as triggered using en/httpevent.asp.
Published: 2015-05-14
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2014-1964 Multiple cross-site scripting (XSS) vulnerabilities in Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam Original Range YCB001, YCW001, running firmware 4.30 and earlier, allow remote authenticated users to inject arbitrary web script or HTML via the (1) SYSCONTACT parameter to form/identityApply, as triggered using en/identity.asp; (2) PASSWD parameter to form/accAdd, as triggered using en/account/accedit.asp; (3) NTPSERVER parameter to form/clockApply, as triggered using en/clock.asp; (4) SERVER parameter to form/smtpclientApply, as triggered using en/smtpclient.asp; (5) SERVER parameter to form/ftpApply, as triggered using en/ftp.asp; or (6) SERVER parameter to form/httpEventApply, as triggered using en/httpevent.asp.
History

No history.

Subscriptions

Y-cam Ycb001 Ycb001 Firmware Ycb002 Ycb002 Firmware Ycb003 Ycb003 Firmware Ycb004 Ycb004 Firmware Ycbl03 Ycbl03 Firmware Ycblb3 Ycblb3 Firmware Ycblhd5 Ycblhd5 Firmware Yceb03 Yceb03 Firmware Yck002 Yck002 Firmware Yck003 Yck003 Firmware Yck004 Yck004 Firmware Ycw001 Ycw001 Firmware Ycw002 Ycw002 Firmware Ycw003 Ycw003 Firmware Ycw004 Ycw004 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T09:58:15.951Z

Reserved: 2014-02-07T00:00:00.000Z

Link: CVE-2014-1902

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-05-14T00:59:02.537

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-1902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses