Asteriskguru Queue Statistics been detected a reflected XSS vulnerability in Asteriskguru Queue Statistics , that allows the execution of arbitrary HTML/script code to be executed in the context of the victim user's browser.
Credit:
The information has been provided by Manuel Garcia Cardenas.
Vulnerable Systems:
* All Versions of Asteriskguru Queue Statistics.
An attacker can execute arbitrary HTML or script code in a targeted user's browser, this can leverage to steal sensitive information as user credentials, personal data, etc.
Vendor Status:
Currently, the vendor had not issued any updates for this vulnerability.
Disclosure Timeline:
January 22, 2013 : Vulnerability acquired by Internet Security Auditors
January - February: Attempts to contact someone managing the project without answer.
March 10, 2013 : Send to lists.