SnapStream PVS Lite Cross-Site Scripting Vulnerability
BID:9375
Info
SnapStream PVS Lite Cross-Site Scripting Vulnerability
| Bugtraq ID: | 9375 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0046 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2004 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Discovery is credited to Rafel Ivgi. |
| Vulnerable: |
Snapstream Personal Video Station Lite 2.0 |
| Not Vulnerable: | |
Discussion
SnapStream PVS Lite Cross-Site Scripting Vulnerability
SnapStream PVS Lite is prone to a cross-site scripting vulnerability.
An attacker could exploit this issue by enticing a victim user to follow a malicious link to a system hosting the software that contains embedded HTML and script code. The embedded code may be rendered in the web browser of the victim user.
This could be exploited to steal cookie-based authentication credentials from legitimate users. Other attacks are also possible.
SnapStream PVS Lite is prone to a cross-site scripting vulnerability.
An attacker could exploit this issue by enticing a victim user to follow a malicious link to a system hosting the software that contains embedded HTML and script code. The embedded code may be rendered in the web browser of the victim user.
This could be exploited to steal cookie-based authentication credentials from legitimate users. Other attacks are also possible.
Exploit / POC
SnapStream PVS Lite Cross-Site Scripting Vulnerability
The following example was provided:
http://www.example.com/?"><script>alert('XSS')</script>
The following example was provided:
http://www.example.com/?"><script>alert('XSS')</script>
Solution / Fix
SnapStream PVS Lite Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.