Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Icecast Server Status Display Cross-Site Scripting Vulnerability

Reportedly Icecast Server is affected by a cross-site scripting vulnerability in the status display functionality. This issue is due to a failure of the application to properly sanitize user-supplied input.

As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of an unsuspecting user when followed. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.







 

Privacy Statement
Copyright 2008, SecurityFocus