Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.804530
Categoría:Web application abuses
Título:WordPress VideoWhisper Live Streaming Integration Multiple Vulnerabilities
Resumen:WordPress VideoWhisper Live Streaming Integration Plugin is prone to multiple vulnerabilities.
Descripción:Summary:
WordPress VideoWhisper Live Streaming Integration Plugin is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to an:

- Improper verification of file extensions before uploading files to the server
in '/videowhisper-live-streaming-integration/ls/vw_snapshots.php'

- Input passed via HTTP POST parameters 'msg' to /ls/vc_chatlog.php, 'm' to
/ls/lb_status.php, 'ct' to /ls/lb_status.php and /ls/v_status.php.

- Input passed via HTTP GET parameters 'n' to /ls/channel.php, htmlchat.php,
ls/video.php, and /videotext.php, 'message' to /ls/lb_logout.php, and 's'
to rtmp_login.php and rtmp_logout.php scripts.

Vulnerability Impact:
Successful exploitation will allow attacker to execute arbitrary HTML and
script code in a user's browser session in the context of an affected site and
read/delete arbitrary files.

Affected Software/OS:
WordPress VideoWhisper Live Streaming Integration Plugin version 4.27.3
and probably prior.

Solution:
Update to version 4.29.5 or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2014-1906
http://packetstormsecurity.com/files/125454
https://www.htbridge.com/advisory/HTB23199
XForce ISS Database: videowhisper-cve20141906-xss(91477)
https://exchange.xforce.ibmcloud.com/vulnerabilities/91477
Common Vulnerability Exposure (CVE) ID: CVE-2014-1907
XForce ISS Database: videowhisper-cve20141907-dir-trav(91478)
https://exchange.xforce.ibmcloud.com/vulnerabilities/91478
Common Vulnerability Exposure (CVE) ID: CVE-2014-1905
Common Vulnerability Exposure (CVE) ID: CVE-2014-1908
CopyrightCopyright (C) 2014 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.