PY Software Active Webcam Webserver Cross-Site Scripting Vulnerability
BID:9261
Info
PY Software Active Webcam Webserver Cross-Site Scripting Vulnerability
| Bugtraq ID: | 9261 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2003 12:00AM |
| Updated: | Dec 19 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
PY Software Active WebCam 4.3 |
| Not Vulnerable: | |
Discussion
PY Software Active Webcam Webserver Cross-Site Scripting Vulnerability
A vulnerability has been reported to be present in the software that may allow a remote attacker to execute HTML or script code in a user's browser.
It has been reported that the problem arises when the software returns an error message to the user that may contain unsanitized data. The script code would run in the context of the user running the vulnerable software.
A vulnerability has been reported to be present in the software that may allow a remote attacker to execute HTML or script code in a user's browser.
It has been reported that the problem arises when the software returns an error message to the user that may contain unsanitized data. The script code would run in the context of the user running the vulnerable software.
Exploit / POC
PY Software Active Webcam Webserver Cross-Site Scripting Vulnerability
http://www.example.com:8080/<script>alert('XSS example');</script>
http://www.example.com:8080/<script>alert('XSS example');</script>
Solution / Fix
PY Software Active Webcam Webserver Cross-Site Scripting Vulnerability
Solution:
The vendor has released a patched version of the software. It has been reported that Active Webcam version 4.3 released after December 17, 2003 is not vulnerable to this issue.
Solution:
The vendor has released a patched version of the software. It has been reported that Active Webcam version 4.3 released after December 17, 2003 is not vulnerable to this issue.
References
PY Software Active Webcam Webserver Cross-Site Scripting Vulnerability
References:
References:
- Active Webcam Product Page (PY Software)
- Directory traversal and XSS in Active Webcam <= 4.3 (Luigi Auriemma
)