Release date:
Updated on:
Affected Systems:
Nikeplus fuelband
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55064
Nike + FuelBand is a high-tech sports wristband developed by Nike. It records your daily exercise volume in a unique way. Its powerful functions allow people to enjoy sports better.
Nike + FuelBand has multiple HTML Injection Vulnerabilities. Attackers can inject HTML and JS Code to affected sites, steal Cookie authentication creden。, and control the appearance of affected sites.
<* Source: Benjamin Kunz Mejri
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Nikeplus
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://nikeplus.nike.com/plus/products/fuelband