WiredRed E/POP Web Conferencing HTML Injection Vulnerability
BID:16542
Info
WiredRed E/POP Web Conferencing HTML Injection Vulnerability
| Bugtraq ID: | 16542 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0643 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2006 12:00AM |
| Updated: | Mar 01 2007 10:05PM |
| Credit: | Discovered by Adrian Castro <[email protected]>. |
| Vulnerable: |
WiredRed e/pop Web Conferencing 4.1 755 |
| Not Vulnerable: | |
Discussion
WiredRed E/POP Web Conferencing HTML Injection Vulnerability
WiredRed e/pop Web Conferencing is prone to an HTML-injection vulnerability.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
e/pop Web Conferencing 4.1.0.755 is reportedly vulnerable. Other versions may be affected as well.
WiredRed e/pop Web Conferencing is prone to an HTML-injection vulnerability.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
e/pop Web Conferencing 4.1.0.755 is reportedly vulnerable. Other versions may be affected as well.
Exploit / POC
WiredRed E/POP Web Conferencing HTML Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
WiredRed E/POP Web Conferencing HTML Injection Vulnerability
Solution:
Version 4.5 Release Build 4.5.0.1210 is available to address this issue; please see the references for more information.
WiredRed e/pop Web Conferencing 4.1 755
Solution:
Version 4.5 Release Build 4.5.0.1210 is available to address this issue; please see the references for more information.
WiredRed e/pop Web Conferencing 4.1 755
-
WiredRed e/pop Web & Video Conferencing 4.5 Release Build 4.5.0.1210
http://www.wiredred.com/web-conferencing-download/
References
WiredRed E/POP Web Conferencing HTML Injection Vulnerability
References:
References:
- e/pop Web & Video Conferencing Revision History (e/pop)
- WiredRed Home Page (WiredRed)
- WiredRed EPOP XSS Vulnerability (Adrian Castro
)