CVE-2001-1199
agora.cgi 3.0a-4.0g - Cross-Site Scripting via cart_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2001-1199. PoCs published by Tamer Sahin.
AI-analyzed exploit summary This is a writeup describing a cross-site scripting (XSS) vulnerability in Agora.cgi when debug mode is enabled. The vulnerability allows an attacker to inject malicious script code via the cart_id parameter, which executes in the context of the victim's session.
Description
Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter.
Exploits (1)
This is a writeup describing a cross-site scripting (XSS) vulnerability in Agora.cgi when debug mode is enabled. The vulnerability allows an attacker to inject malicious script code via the cart_id parameter, which executes in the context of the victim's session.