Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 and M10, and other versions before for M10/D10 and for M22, allow remote attackers to inject arbitrary web script or HTML via URL-encoded values in (1) the query string to help/help, (2) the get_image_info_abspath parameter to control/eventplayer, and (3) the source_ip parameter to events.tar.


 Vendor: Mobotix
Mobotix ip network camera
S14 firmware

