Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way Video Chat component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the r parameter to index.php.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| videowhisper | php_2_way_video_chat | * |
Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration plugin 4.25.3 and possibly earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameter. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| videowhisper | videowhisper_live_streaming_integration | * |
| videowhisper | videowhisper_live_streaming_integration | 2.0 |
| videowhisper | videowhisper_live_streaming_integration | 4.05 |
| videowhisper | videowhisper_live_streaming_integration | 1.0.2 |
| videowhisper | videowhisper_live_streaming_integration | 2.1 |
| videowhisper | videowhisper_live_streaming_integration | 4.07 |
| videowhisper | videowhisper_live_streaming_integration | 4.25 |
| videowhisper | videowhisper_live_streaming_integration | 2.2 |
Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, and then accessing the file via a direct request to a wp-content/plugins/videowhisper-live-streaming-integration/ls/snapshots/ pathname, as demonstrated by a .php.jpg filename.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| videowhisper | videowhisper_live_streaming_integration | * |
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter to vc_chatlog.php; n parameter to (3) channel.php, (4) htmlchat.php, (5) video.php, or (6) videotext.php; (7) message parameter to lb_logout.php; or ct parameter to (8) lb_status.php or (9) v_status.php in ls/.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| videowhisper | videowhisper_live_streaming_integration | * |
| videowhisper | videowhisper_live_streaming_integration | 2.0 |
| videowhisper | live_streaming_integration_plugin | 4.27.3 |
| videowhisper | videowhisper_live_streaming_integration | 4.05 |
| videowhisper | videowhisper_live_streaming_integration | 1.0.2 |
| videowhisper | videowhisper_live_streaming_integration | 2.1 |
| videowhisper | videowhisper_live_streaming_integration | 4.07 |
| videowhisper | live_streaming_integration_plugin | 4.27 |
| videowhisper | videowhisper_live_streaming_integration | 2.2 |
| videowhisper | videowhisper_live_streaming_integration | 4.25 |
| videowhisper | videowhisper_live_streaming_integration | 4.25.3 |
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_logout.php.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| videowhisper | videowhisper_live_streaming_integration | * |
| videowhisper | videowhisper_live_streaming_integration | 2.0 |
| videowhisper | live_streaming_integration_plugin | 4.27.3 |
| videowhisper | videowhisper_live_streaming_integration | 4.05 |
| videowhisper | videowhisper_live_streaming_integration | 2.1 |
| videowhisper | videowhisper_live_streaming_integration | 1.0.2 |
| videowhisper | videowhisper_live_streaming_integration | 4.07 |
| videowhisper | videowhisper_live_streaming_integration | 4.25 |
| videowhisper | live_streaming_integration_plugin | 4.27 |
| videowhisper | videowhisper_live_streaming_integration | 2.2 |
| videowhisper | videowhisper_live_streaming_integration | 4.25.3 |
The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| videowhisper | videowhisper_live_streaming_integration | * |
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to ls/htmlchat.php or (2) bgcolor parameter to ls/index.php. NOTE: vector 1 may overlap CVE-2014-1906.4.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| videowhisper | videowhisper_live_streaming_integration | 4.29.6 |
Multiple cross-site scripting (XSS) vulnerabilities in vwrooms\templates\logout.tpl.php in the VideoWhisper Webcam plugins for Drupal 7.x allow remote attackers to inject arbitrary web script or HTML via the (1) module or (2) message parameter to index.php.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| videowhisper | videowhisper | 7.x-1.0 |
| videowhisper | videowhisper | 7.x-1.1 |
| videowhisper | videowhisper | 7.x-1.x |
| videowhisper | videowhisper | 7.x-1.3 |
Cross-site scripting (XSS) vulnerability in posts/videowhisper/r_logout.php in the Video Posts Webcam Recorder plugin 1.55.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| videowhisper | video_posts_webcam_recorder | * |
Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the room_name parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| videowhisper | videowhisper_live_streaming_integration | * |
| videowhisper | videowhisper_live_streaming_integration | 2.0 |
| videowhisper | videowhisper_live_streaming_integration | 4.27.2 |
| videowhisper | videowhisper_live_streaming_integration | 4.05 |
| videowhisper | videowhisper_live_streaming_integration | 1.0.2 |
| videowhisper | videowhisper_live_streaming_integration | 2.1 |
| videowhisper | videowhisper_live_streaming_integration | 4.07 |
| videowhisper | videowhisper_live_streaming_integration | 2.2 |
| videowhisper | videowhisper_live_streaming_integration | 4.25 |
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Video Presentation plugin before 3.31 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) room_name parameter to c_login.php or (2) room parameter to index.php in vp/.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| videowhisper | video_presentation | * |