CVE-2018-11689

Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
References
Link Resource
http://www.securityfocus.com/archive/1/542083/100/0/threaded Exploit Third Party Advisory URL Repurposed VDB Entry
https://drive.google.com/file/d/1aWbvdrx1KRkUv4ikkm530a2N5qrxCLmr/view?usp=sharing Exploit Third Party Advisory
https://seclists.org/bugtraq/2018/Jun/40 Exploit Mailing List Third Party Advisory
https://vulmon.com/vulnerabilitydetails?qid=CVE-2018-11689 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:samsung:smartviewer:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-1642_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-1642:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-842_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-842:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-442_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-442:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-1641_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-1641:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-841_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-841:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-840:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-440_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-440:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:hanwha-security:hrd-443_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-443:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:hanwha-security:srd-1694u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:srd-1694u:-:*:*:*:*:*:*:*

History

24 Apr 2022, 01:54

Type Values Removed Values Added
CPE cpe:2.3:o:hanwha-security:hrd-841_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-840:-:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:srd-1694u:-:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-1641:-:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-443:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-842_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-1642:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-443_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-440_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:srd-1694u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-1642_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-442_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-841:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-1641_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-440:-:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-442:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwha-security:hrd-840_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hanwha-security:hrd-842:-:*:*:*:*:*:*:*
References (MISC) https://drive.google.com/file/d/1aWbvdrx1KRkUv4ikkm530a2N5qrxCLmr/view?usp=sharing - (MISC) https://drive.google.com/file/d/1aWbvdrx1KRkUv4ikkm530a2N5qrxCLmr/view?usp=sharing - Exploit, Third Party Advisory
References (BUGTRAQ) http://www.securityfocus.com/archive/1/542083/100/0/threaded - Exploit, Third Party Advisory, VDB Entry (BUGTRAQ) http://www.securityfocus.com/archive/1/542083/100/0/threaded - Exploit, Third Party Advisory, URL Repurposed, VDB Entry
References (MISC) https://seclists.org/bugtraq/2018/Jun/40 - (MISC) https://seclists.org/bugtraq/2018/Jun/40 - Exploit, Mailing List, Third Party Advisory

04 Jan 2022, 04:15

Type Values Removed Values Added
References
  • (MISC) https://seclists.org/bugtraq/2018/Jun/40 -
  • (MISC) https://drive.google.com/file/d/1aWbvdrx1KRkUv4ikkm530a2N5qrxCLmr/view?usp=sharing -
Summary Smart Viewer in Samsung Web Viewer for Samsung DVR is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)

Information

Published : 2018-06-14 20:29

Updated : 2024-02-04 19:46


NVD link : CVE-2018-11689

Mitre link : CVE-2018-11689

CVE.ORG link : CVE-2018-11689


JSON object : View

Products Affected

samsung

  • smartviewer

hanwha-security

  • hrd-1642
  • hrd-1641_firmware
  • hrd-841
  • hrd-841_firmware
  • hrd-443_firmware
  • hrd-840_firmware
  • hrd-1641
  • hrd-440
  • hrd-840
  • hrd-1642_firmware
  • hrd-842_firmware
  • hrd-443
  • srd-1694u_firmware
  • srd-1694u
  • hrd-842
  • hrd-442_firmware
  • hrd-440_firmware
  • hrd-442
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')