CVE-2002-1785
Zeus Web Server 4.0-4.1r2 - Authenticated Cross-Site Scripting via Section Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-1785. PoCs published by euronymous.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in the Zeus Web Server's administration interface. The vulnerability allows arbitrary HTML and script code execution in the context of a user's web client when they visit a malicious link.
Description
Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remote authenticated users to inject arbitrary web script or HTML via the section parameter to index.fcgi.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in the Zeus Web Server's administration interface. The vulnerability allows arbitrary HTML and script code execution in the context of a user's web client when they visit a malicious link.