[<prev] [next>] [day] [month] [year] [list]
Message-Id: <200811041807.mA4I7PFn018971@www3.securityfocus.com>
Date: Tue, 4 Nov 2008 11:07:25 -0700
From: brad.antoniewicz@...ndstone.com
To: bugtraq@...urityfocus.com
Subject: FirmChannel Digital Signage 3.24 Cross-site scripting
Title: FirmChannel Digital Signage 3.24 Cross-site scripting
-------------------------------------------------------------
Vendor: FirmChannel
Vendor URL: www.firmchannel.com
Vendor Response: Vendor has been notified and has since addressed the issue in the latest software release.
Description:
A cross-site scripting vulnerability is present within Firm Channel's Indoor & Outdoor Digital SIGNAGE version 3.24 (and potentially below).
Example:
http://host/index.php?module=account&action=login%3Cscript%3Ealert(%27xss%27);%3C/script%3E
Patch Information:
Firm Channel has addressed the issue in the latest version.
For more information visit firmchannel.com
CVE: CVE-2008-4931
Credit:
Brad Antoniewicz
brad.antoniewicz@...ndstone.com
Powered by blists - more mailing lists