- EPSS 0.35%
- Veröffentlicht 06.05.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 sends configuration data in response to a Setup Wizard remote-management command, which allows remote attackers to obtain sensitive information such as passwords by re...
CVE-2009-1556
- EPSS 0.23%
- Veröffentlicht 06.05.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
img/main.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote authenticated users to read arbitrary files in img/ via a filename in the next_file parameter, as demonstrated by reading .htpasswd to ob...
CVE-2009-1557
- EPSS 6.88%
- Veröffentlicht 06.05.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allow remote attackers to inject arbitrary web script or HTML via the next_file parameter to (1) main.cgi, (2) i...
CVE-2009-1558
- EPSS 10.88%
- Veröffentlicht 06.05.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote attackers to read arbitrary files via a %2e. (encoded dot dot) or an absolute pathname in the next_f...
CVE-2009-1559
- EPSS 0.19%
- Veröffentlicht 06.05.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Absolute path traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R24 and possibly 1.00R22 allows remote attackers to read arbitrary files via an absolute pathname in the this_file parameter. ...