PT-2006-1700 · Wiredred · Wiredred E/Pop Web Conferencing

Adrian Castro

·

Published

2006-02-10

·

Updated

2018-10-19

·

CVE-2006-0643

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions WiredRed e/pop Web Conferencing version 4.1.0.755
Description The issue is related to a cross-site scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML. This is achieved by manipulating the topic name of a conference.
Recommendations For version 4.1.0.755, consider restricting the ability to create or modify conference topic names to prevent arbitrary web script or HTML injection until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0643

Affected Products

Wiredred E/Pop Web Conferencing