PT-2008-2070 · Novemberborn · Novemberborn Sifr
Jan Fry
·
Published
2008-01-23
·
Updated
2018-10-15
·
CVE-2008-0438
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Novemberborn sIFR version 2.0.2
Description
The issue is related to a cross-site scripting (XSS) vulnerability in the font rendering functionality. This allows remote attackers to inject arbitrary web script or HTML via the
txt parameter to a Flash (SWF) file.Recommendations
For Novemberborn sIFR version 2.0.2, consider restricting access to the vulnerable
txt parameter in Flash files until a patch is available. As a temporary workaround, avoid using the txt parameter in the affected API endpoint or SWF files.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Novemberborn Sifr