Vulnerabilities > CVE-2006-3624 - Cross-Site Scripting vulnerability in FLV Player 8

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
flv
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url parameter to (1) player.php or (2) popup.php.

Vulnerable Configurations

Part Description Count
Application
Flv
1

Exploit-Db

  • descriptionFLV Players 8 player.php url Parameter XSS. CVE-2006-3624. Remote exploits for multiple platform
    idEDB-ID:28209
    last seen2016-02-03
    modified2006-07-12
    published2006-07-12
    reporterxzerox
    sourcehttps://www.exploit-db.com/download/28209/
    titleFLV Players 8 player.php url Parameter XSS
  • descriptionFLV Players 8 popup.php url Parameter XSS. CVE-2006-3624. Remote exploits for multiple platform
    idEDB-ID:28210
    last seen2016-02-03
    modified2006-07-12
    published2006-07-12
    reporterxzerox
    sourcehttps://www.exploit-db.com/download/28210/
    titleFLV Players 8 popup.php url Parameter XSS