PT-2014-4356 · Videowhisper · Videowhisper Live Streaming Integration

Published

2014-03-06

·

Updated

2025-11-03

·

CVE-2014-1906

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions VideoWhisper Live Streaming Integration plugin versions prior to 4.29.5
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via various parameters in different files, including the m parameter to "lb status.php", the msg parameter to "vc chatlog.php", the n parameter to "channel.php", "htmlchat.php", "video.php", or "videotext.php", the message parameter to "lb logout.php", or the ct parameter to "lb status.php" or "v status.php" in the "ls/" directory.
Recommendations For VideoWhisper Live Streaming Integration plugin versions prior to 4.29.5, update to version 4.29.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable parameters, such as m, msg, n, message, and ct, in the affected files until a patch is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2014-1906

Affected Products

Videowhisper Live Streaming Integration