Back to list
|
Post reply
FirmChannel Digital Signage 3.24 Cross-site scripting
Nov 04 2008 06:07PM
brad antoniewicz foundstone com
Title: FirmChannel Digital Signage 3.24 Cross-site scripting
-------------------------------------------------------------
Vendor: FirmChannel
Vendor URL: www.firmchannel.com
Vendor Response: Vendor has been notified and has since addressed the issue in the latest software release.
Description:
A cross-site scripting vulnerability is present within Firm Channel's Indoor & Outdoor Digital SIGNAGE version 3.24 (and potentially below).
Example:
http://host/index.php?module=account&action=login%3Cscript%3Ealert(%27xs
s%27);%3C/script%3E
Patch Information:
Firm Channel has addressed the issue in the latest version.
For more information visit firmchannel.com
CVE: CVE-2008-4931
Credit:
Brad Antoniewicz
brad.antoniewicz (at) foundstone (dot) com [email concealed]
[ reply ]
Privacy Statement
Copyright 2010, SecurityFocus
-------------------------------------------------------------
Vendor: FirmChannel
Vendor URL: www.firmchannel.com
Vendor Response: Vendor has been notified and has since addressed the issue in the latest software release.
Description:
A cross-site scripting vulnerability is present within Firm Channel's Indoor & Outdoor Digital SIGNAGE version 3.24 (and potentially below).
Example:
http://host/index.php?module=account&action=login%3Cscript%3Ealert(%27xs
s%27);%3C/script%3E
Patch Information:
Firm Channel has addressed the issue in the latest version.
For more information visit firmchannel.com
CVE: CVE-2008-4931
Credit:
Brad Antoniewicz
brad.antoniewicz (at) foundstone (dot) com [email concealed]
[ reply ]