CVE-2018-11689

Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
References
Link Resource
http://www.securityfocus.com/archive/1/542083/100/0/threaded Exploit Third Party Advisory URL Repurposed VDB Entry
https://drive.google.com/file/d/1aWbvdrx1KRkUv4ikkm530a2N5qrxCLmr/view?usp=sharing Exploit Third Party Advisory
https://seclists.org/bugtraq/2018/Jun/40 Exploit Mailing List Third Party Advisory
https://vulmon.com/vulnerabilitydetails?qid=CVE-2018-11689 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:samsung:smartviewer:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-1642_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-1642:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-842_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-842:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-442_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-442:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-1641_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-1641:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-841_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-841:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-840:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-440_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-440:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-443_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-443:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:hanwha-security:srd-1694u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:srd-1694u:-:*:*:*:*:*:*:*

History

24 Apr 2022, 01:54

Type Values Removed Values Added
CPE cpe:2.3:h:hanwha-security:hrd-1642:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-443_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-841:-:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:srd-1694u:-:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-443:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:srd-1694u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-440_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-842_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-840:-:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-1641:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-841_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-1642_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-442_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-1641_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-442:-:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-440:-:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-842:-:*:*:*:*:*:*:*
References (MISC) https://drive.google.com/file/d/1aWbvdrx1KRkUv4ikkm530a2N5qrxCLmr/view?usp=sharing - (MISC) https://drive.google.com/file/d/1aWbvdrx1KRkUv4ikkm530a2N5qrxCLmr/view?usp=sharing - Exploit, Third Party Advisory
References (MISC) https://seclists.org/bugtraq/2018/Jun/40 - (MISC) https://seclists.org/bugtraq/2018/Jun/40 - Exploit, Mailing List, Third Party Advisory
References (BUGTRAQ) http://www.securityfocus.com/archive/1/542083/100/0/threaded - Exploit, Third Party Advisory, VDB Entry (BUGTRAQ) http://www.securityfocus.com/archive/1/542083/100/0/threaded - Exploit, Third Party Advisory, URL Repurposed, VDB Entry
First Time Hanwha-security hrd-440
Hanwha-security hrd-442
Hanwha-security hrd-842
Hanwha-security hrd-841 Firmware
Hanwha-security hrd-840
Hanwha-security hrd-443
Hanwha-security hrd-840 Firmware
Hanwha-security hrd-841
Hanwha-security hrd-1641 Firmware
Hanwha-security hrd-442 Firmware
Hanwha-security srd-1694u Firmware
Hanwha-security
Hanwha-security hrd-1642 Firmware
Hanwha-security hrd-1641
Hanwha-security hrd-842 Firmware
Hanwha-security hrd-440 Firmware
Hanwha-security srd-1694u
Hanwha-security hrd-1642
Hanwha-security hrd-443 Firmware

04 Jan 2022, 04:15

Type Values Removed Values Added
References
  • (MISC) https://drive.google.com/file/d/1aWbvdrx1KRkUv4ikkm530a2N5qrxCLmr/view?usp=sharing -
  • (MISC) https://seclists.org/bugtraq/2018/Jun/40 -
Summary Smart Viewer in Samsung Web Viewer for Samsung DVR is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)

Information

Published : 2018-06-14 20:29

Updated : 2023-12-10 12:30


NVD link : CVE-2018-11689

Mitre link : CVE-2018-11689

CVE.ORG link : CVE-2018-11689


JSON object : View

Products Affected

hanwha-security

  • hrd-841_firmware
  • hrd-1641
  • hrd-1642
  • hrd-440_firmware
  • hrd-840_firmware
  • hrd-841
  • hrd-840
  • srd-1694u_firmware
  • srd-1694u
  • hrd-1641_firmware
  • hrd-443_firmware
  • hrd-842
  • hrd-443
  • hrd-442
  • hrd-442_firmware
  • hrd-1642_firmware
  • hrd-440
  • hrd-842_firmware

samsung

  • smartviewer
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')