CVE-2014-1906

VideoWhisper Live Streaming Integration <4.29.5 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter to vc_chatlog.php; n parameter to (3) channel.php, (4) htmlchat.php, (5) video.php, or (6) videotext.php; (7) message parameter to lb_logout.php; or ct parameter to (8) lb_status.php or (9) v_status.php in ls/.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/31986

Scores

EPSS 0.0122
EPSS Percentile 78.9%

Details

CWE
CWE-79
Status published
Products (12)
videowhisper/live_streaming_integration_plugin
videowhisper/live_streaming_integration_plugin
videowhisper/videowhisper_live_streaming_integration < 4.27.4
videowhisper/videowhisper_live_streaming_integration
videowhisper/videowhisper_live_streaming_integration
videowhisper/videowhisper_live_streaming_integration
videowhisper/videowhisper_live_streaming_integration
videowhisper/videowhisper_live_streaming_integration
videowhisper/videowhisper_live_streaming_integration
videowhisper/videowhisper_live_streaming_integration
... and 2 more
Published Mar 06, 2014
Tracked Since Feb 18, 2026