CVE-2008-4931
firmCHANNEL Digital Signage 3.24 - Cross-Site Scripting via Account Module Action Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4931. PoCs published by Brad Antoniewicz.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in firmCHANNEL Indoor & Outdoor Digital SIGNAGE 3.24. It includes a proof-of-concept URL demonstrating the vulnerability but does not contain executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in the account module in firmCHANNEL Digital Signage 3.24, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the action parameter to index.php.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in firmCHANNEL Indoor & Outdoor Digital SIGNAGE 3.24. It includes a proof-of-concept URL demonstrating the vulnerability but does not contain executable exploit code.