Webcam Corp Webcam Watchdog sresult.exe Cross-Site Scripting Vulnerability
BID:10837
Info
Webcam Corp Webcam Watchdog sresult.exe Cross-Site Scripting Vulnerability
| Bugtraq ID: | 10837 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2004 12:00AM |
| Updated: | Aug 02 2004 12:00AM |
| Credit: | Discovery of this issue is credited to Dr_Insane <[email protected]>. |
| Vulnerable: |
Webcam Corp Webcam Watchdog 4.0.1 a |
| Not Vulnerable: | |
Discussion
Webcam Corp Webcam Watchdog sresult.exe Cross-Site Scripting Vulnerability
Reportedly Webcam Corp Webcam Watchdog is affected by a remote cross-site scripting vulnerability in the sresult.exe binary. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated web content.
As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of a legitimate user. Specifically the attacker can pass malicious HTML code as a value for the affected URI parameter supplied to 'sresult.exe'. All code will be executed within the context of the website running the vulnerable software.
Reportedly Webcam Corp Webcam Watchdog is affected by a remote cross-site scripting vulnerability in the sresult.exe binary. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated web content.
As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of a legitimate user. Specifically the attacker can pass malicious HTML code as a value for the affected URI parameter supplied to 'sresult.exe'. All code will be executed within the context of the website running the vulnerable software.
Exploit / POC
Webcam Corp Webcam Watchdog sresult.exe Cross-Site Scripting Vulnerability
No exploit is required to leverage this issue. The following proof of concept has been provided:
http://www.example.com/sresult.exe?cam=[code]
No exploit is required to leverage this issue. The following proof of concept has been provided:
http://www.example.com/sresult.exe?cam=[code]
Solution / Fix
Webcam Corp Webcam Watchdog sresult.exe Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Webcam Corp Webcam Watchdog sresult.exe Cross-Site Scripting Vulnerability
References:
References: