vendor:
PVS Lite
by:
SecurityFocus
4.3
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: PVS Lite
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
SnapStream PVS Lite Cross-Site Scripting Vulnerability
SnapStream PVS Lite is prone to a cross-site scripting vulnerability. An attacker could exploit this issue by enticing a victim user to follow a malicious link to a system hosting the software that contains embedded HTML and script code. The embedded code may be rendered in the web browser of the victim user. This could be exploited to steal cookie-based authentication credentials from legitimate users. Other attacks are also possible.
Mitigation:
Input validation should be used to ensure that user-supplied data does not contain malicious code.