what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

WiredRedXSS.txt

WiredRedXSS.txt
Posted Feb 9, 2006
Authored by Adrian Castro

WiredRed EPOP WebConference server version 4.1.0.755 is susceptible to cross site scripting attacks.

tags | advisory, xss
SHA-256 | f3e8e0574ab17e4c3f798104da79baf6a7b5c08a39a3ee1660311c042a69f832

WiredRedXSS.txt

Change Mirror Download
WiredRed EPOP XSS Vulnerability

---Summary---

Software Affected: EPOP WebConference Server
Software Versions: 4.1.0.755
Vendors URL: www.wiredred.com
Vulnerability Type: Cross Site Scripting
Proof of Concept: An exploit is not required
Threat Level: Low

---Product Description---

e/pop from WiredRed provides a complete solution for all of your real-time communications requirements: web and desktop video conferencing, secure IM and alert messaging. As a user, you'll love the hassle free interface and breadth of options that will enhance your training, sales and collaboration.

---Vulnerability Description---

When creating public or private conferences in e/pop server, the topic name is not properly sanitized. This allows for a xss attack in which every user who visits the root (login) page for the e/pop web server can be fooled into entering their login information on a remote server among other things. By default, e/pop is enabled without or with optional SSL connections to the web server. Any standard authenticated user can perform this attack on all other users or visitors of the web server.

---Solution---

None at this time.

---credit---

Adrian Castro



_____________________________________________________________
Thank you for choosing LinuxQuestions.
http://www.linuxquestions.org
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close