HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/151119/HMS-Netbiter-WS100-3.30.5-Cross-Site-Scripting.html | Exploit Third Party Advisory VDB Entry |
https://seclists.org/bugtraq/2019/Jan/9 | Exploit Mailing List Third Party Advisory |
https://www.hms-networks.com/docs/librariesprovider6/cybersecurity/hms-security-advisory-2018-12-04-001-ec150-ec250-lc310-lc350-ws100-ws200-cve-2018-19694.pdf | Patch Vendor Advisory |
https://www.netbiter.com/products | Product Third Party Advisory |
http://packetstormsecurity.com/files/151119/HMS-Netbiter-WS100-3.30.5-Cross-Site-Scripting.html | Exploit Third Party Advisory VDB Entry |
https://seclists.org/bugtraq/2019/Jan/9 | Exploit Mailing List Third Party Advisory |
https://www.hms-networks.com/docs/librariesprovider6/cybersecurity/hms-security-advisory-2018-12-04-001-ec150-ec250-lc310-lc350-ws100-ws200-cve-2018-19694.pdf | Patch Vendor Advisory |
https://www.netbiter.com/products | Product Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
History
No history.
Information
Published : 2019-03-21 16:00
Updated : 2024-11-21 03:58
NVD link : CVE-2018-19694
Mitre link : CVE-2018-19694
CVE.ORG link : CVE-2018-19694
JSON object : View
Products Affected
hms-networks
- netbiter_lc310
- netbiter_ec250
- netbiter_ws200_firmware
- netbiter_ws100_firmware
- netbiter_ws100
- netbiter_ws200
- netbiter_lc310_firmware
- netbiter_ec250_firmware
- netbiter_ec150_firmware
- netbiter_lc350_thingworx_firmware
- netbiter_lc350_firmware
- netbiter_lc350_thingworx
- netbiter_lc310_thingworx_firmware
- netbiter_ec150
- netbiter_lc310_thingworx
- netbiter_lc350
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')