RSS   Vulnerabilities for 'Flv player'   RSS

2006-07-18
 
CVE-2006-3625

CWE-Other
 

 
FLV Players 8 allows remote attackers to obtain sensitive information via (1) a direct request to paginate.php or (2) an invalid p parameter to player.php, which reveal the path in an error message.

 
 
CVE-2006-3624

CWE-Other
 

 
Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url parameter to (1) player.php or (2) popup.php.

 


Copyright 2024, cxsecurity.com

 

Back to Top