AOH :: HP Unsorted A :: BX2995.HTM

AstroCam XSS



XSS in AstroCam
XSS in AstroCam



XSS in AstroCam 2.5.x/2.6.x/2.7.[123]
-------------------------------------

Software:	AstroCam
Vulnerable:	2.5.0-2.7.3
Not vulnerable:	2.7.4
Class:		Input Validation Error
Remote: 	Yes
Local:		Yes
Credit: 	This issue was announced by the vendor.
Anouncement:	http://wendzel.de/?sub=showpost&blogid=5&postid=56 
Project URL:	http://wendzel.de/?sub=softw&ssub=acam 

Description:

It was possibly to execute HTML embedded script code
in pic.php.

Patch/URL can be found here:
http://sourceforge.net/project/showfiles.php?group_id=85523 

regards
Steffen Wendzel

-- 
http://www.wendzel.de/?sub=steffen 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.