CVE-2018-19694

HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_ws100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_ws100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_ws200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_ws200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_ec150_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_ec150:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_ec250_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_ec250:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_lc310_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_lc310:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_lc310_thingworx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_lc310_thingworx:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_lc350_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_lc350:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hms-networks:netbiter_lc350_thingworx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hms-networks:netbiter_lc350_thingworx:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:58

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/151119/HMS-Netbiter-WS100-3.30.5-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/151119/HMS-Netbiter-WS100-3.30.5-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry
References () https://seclists.org/bugtraq/2019/Jan/9 - Exploit, Mailing List, Third Party Advisory () https://seclists.org/bugtraq/2019/Jan/9 - Exploit, Mailing List, Third Party Advisory
References () https://www.hms-networks.com/docs/librariesprovider6/cybersecurity/hms-security-advisory-2018-12-04-001-ec150-ec250-lc310-lc350-ws100-ws200-cve-2018-19694.pdf - Patch, Vendor Advisory () https://www.hms-networks.com/docs/librariesprovider6/cybersecurity/hms-security-advisory-2018-12-04-001-ec150-ec250-lc310-lc350-ws100-ws200-cve-2018-19694.pdf - Patch, Vendor Advisory
References () https://www.netbiter.com/products - Product, Third Party Advisory () https://www.netbiter.com/products - Product, Third Party Advisory

Information

Published : 2019-03-21 16:00

Updated : 2024-11-21 03:58


NVD link : CVE-2018-19694

Mitre link : CVE-2018-19694

CVE.ORG link : CVE-2018-19694


JSON object : View

Products Affected

hms-networks

  • netbiter_lc310
  • netbiter_ec250
  • netbiter_ws200
  • netbiter_lc310_thingworx_firmware
  • netbiter_lc350
  • netbiter_lc310_thingworx
  • netbiter_ec150
  • netbiter_ec250_firmware
  • netbiter_lc350_thingworx
  • netbiter_ws100
  • netbiter_lc310_firmware
  • netbiter_lc350_thingworx_firmware
  • netbiter_lc350_firmware
  • netbiter_ec150_firmware
  • netbiter_ws100_firmware
  • netbiter_ws200_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')