Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2025-0576
Disclosure Date: January 20, 2025 (last updated January 20, 2025)
A vulnerability was found in Mobotix M15 4.3.4.83 and classified as problematic. This issue affects some unknown processing of the file /control/player?center&eventlist&pda&dummy_for_reload=1736177631&p_evt. The manipulation of the argument p_qual leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-47917
Disclosure Date: December 30, 2024 (last updated January 02, 2025)
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
0
Attacker Value
Unknown
CVE-2022-30018
Disclosure Date: May 19, 2022 (last updated February 23, 2025)
Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverable Format via the MxCC.ini config file. The credential storage method in this software enables an attacker/user of the machine to gain admin access to the software and gain access to recordings/recording locations.
0
Attacker Value
Unknown
CVE-2019-12502
Disclosure Date: May 31, 2019 (last updated November 27, 2024)
There is a lack of CSRF countermeasures on MOBOTIX S14 MX-V4.2.1.61 cameras, as demonstrated by adding an admin account via the /admin/access URI.
0
Attacker Value
Unknown
CVE-2009-5154
Disclosure Date: February 09, 2019 (last updated November 27, 2024)
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. There is a default password of meinsm for the admin account.
0
Attacker Value
Unknown
CVE-2019-7673
Disclosure Date: February 09, 2019 (last updated November 27, 2024)
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. Administrator Credentials are stored in the 13-character DES hash format.
0
Attacker Value
Unknown
CVE-2019-7675
Disclosure Date: February 09, 2019 (last updated November 27, 2024)
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleartext HTTP with Basic Authentication, as demonstrated by the /admin/index.html URI.
0
Attacker Value
Unknown
CVE-2019-7674
Disclosure Date: February 09, 2019 (last updated November 27, 2024)
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. /admin/access accepts a request to set the "aaaaa" password, considered insecure for some use cases, from a user.
0
Attacker Value
Unknown
CVE-2006-2490
Disclosure Date: May 19, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before 2.2.3.18 for M10/D10 and 3.0.3.31 for M22, allow remote attackers to inject arbitrary web script or HTML via URL-encoded values in (1) the query string to help/help, (2) the get_image_info_abspath parameter to control/eventplayer, and (3) the source_ip parameter to events.tar.
0