4.3
CVSSv2

CVE-2014-1906

Published: 06/03/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin prior to 4.29.5 for WordPress allow remote malicious users to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter to vc_chatlog.php; n parameter to (3) channel.php, (4) htmlchat.php, (5) video.php, or (6) videotext.php; (7) message parameter to lb_logout.php; or ct parameter to (8) lb_status.php or (9) v_status.php in ls/.

Vulnerable Product Search on Vulmon Subscribe to Product

videowhisper live streaming integration plugin

videowhisper live streaming integration plugin 4.25.3

videowhisper live streaming integration plugin 1.0.2

videowhisper live streaming integration plugin 4.25

videowhisper live streaming integration plugin 4.07

videowhisper live streaming integration plugin 4.27

videowhisper live streaming integration plugin 4.27.3

videowhisper live streaming integration plugin 2.1

videowhisper live streaming integration plugin 2.0

videowhisper live streaming integration plugin 4.05

videowhisper live streaming integration plugin 2.2

Exploits

Advisory ID: HTB23199 Product: VideoWhisper Live Streaming Integration Vendor: VideoWhisper Vulnerable Version(s): 4273 and probably prior Tested Version: 4273 Advisory Publication: February 6, 2014 [without technical details] Vendor Notification: February 6, 2014 Vendor Patch: February 7, 2014 Public Disclosure: February 27, 2014 Vulnerability ...
VideoWhisper Live Streaming Integration version 4273 suffers from cross site scripting, remote shell upload, information exposure, and path traversal vulnerabilities ...