PT-2008-2070 · Novemberborn · Novemberborn Sifr

Jan Fry

·

Published

2008-01-23

·

Updated

2018-10-15

·

CVE-2008-0438

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Novemberborn sIFR version 2.0.2
Description The issue is related to a cross-site scripting (XSS) vulnerability in the font rendering functionality. This allows remote attackers to inject arbitrary web script or HTML via the txt parameter to a Flash (SWF) file.
Recommendations For Novemberborn sIFR version 2.0.2, consider restricting access to the vulnerable txt parameter in Flash files until a patch is available. As a temporary workaround, avoid using the txt parameter in the affected API endpoint or SWF files.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0438

Affected Products

Novemberborn Sifr