PT-2006-1700 · Wiredred · Wiredred E/Pop Web Conferencing

Adrian Castro

·

Publicado

2006-02-10

·

Atualizado

2018-10-19

·

CVE-2006-0643

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions WiredRed e/pop Web Conferencing version 4.1.0.755
Description The issue is related to a cross-site scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML. This is achieved by manipulating the topic name of a conference.
Recommendations For version 4.1.0.755, consider restricting the ability to create or modify conference topic names to prevent arbitrary web script or HTML injection until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0643

Produtos afetados

Wiredred E/Pop Web Conferencing