CVE-2003-0416
Bandmin 1.4 - Cross-Site Scripting via Year, Month, or Host Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-0416. PoCs published by silent needel.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Bandmin, where malicious scripts can be injected via the 'year', 'month', or 'host' parameters in specific URLs. No actual exploit code is present, only a description of the vulnerability and example URLs.
Description
Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year parameter in a showmonth action, (2) the month parameter in a showmonth action, or (3) the host parameter in a showhost action.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in Bandmin, where malicious scripts can be injected via the 'year', 'month', or 'host' parameters in specific URLs. No actual exploit code is present, only a description of the vulnerability and example URLs.