49564vdb entry
http://osvdb.org/49564 CVE-2008-4931
firmCHANNEL Indoor & Outdoor Digital Signage 3.24 - Cross-Site Scripting
Record summary
CVE-2008-4931 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in the account module in firmCHANNEL Digital Signage 3.24, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the action parameter to index.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBfirmCHANNEL Indoor & Outdoor Digital Signage 3.24 - Cross-Site ScriptingExploitDB exploitby Brad AntoniewiczNot analyzed1 file
References
532549Third-party advisory
http://secunia.com/advisories/32549 4566Third-party advisory
http://securityreason.com/securityalert/4566 20081104 FirmChannel Digital Signage 3.24 Cross-site scriptingmailing list
http://www.securityfocus.com/archive/1/498042/100/0/threaded nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-4931