vendor:
PHP Webcam Video Conference
by:
vinicius777
7,5
CVSS
HIGH
Local File Include & XSS Reflected
94, 79
CWE
Product Name: PHP Webcam Video Conference
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014
Exploit: PHP Webcam Video Conference – LFI/XSS
The vulnerability exists due to insufficient sanitization of user-supplied input in 's' parameter of 'rtmp_login.php' script and 'message' parameter of 'vc_logout.php' script. A remote attacker can send a specially crafted request to the vulnerable script and execute arbitrary code on the vulnerable system. Also, an attacker can inject arbitrary HTML and script code, which will be executed in user's browser session in context of affected site.
Mitigation:
Upgrade from to the new version on videowhisper vendor homepage.