PT-2006-1700 · Wiredred · Wiredred E/Pop Web Conferencing
Adrian Castro
·
Published
2006-02-10
·
Updated
2018-10-19
·
CVE-2006-0643
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WiredRed e/pop Web Conferencing version 4.1.0.755
Description
The issue is related to a cross-site scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML. This is achieved by manipulating the topic name of a conference.
Recommendations
For version 4.1.0.755, consider restricting the ability to create or modify conference topic names to prevent arbitrary web script or HTML injection until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wiredred E/Pop Web Conferencing