Exploitation Summary
EIP tracks 1 public exploit for CVE-2003-0481. PoCs published by François SORIN.
AI-analyzed exploit summary The exploit describes a cross-site scripting (XSS) vulnerability in Tutos' file_select.php script due to improper input handling. An attacker can inject hostile code via the 'msg' parameter to execute arbitrary JavaScript in the context of a user's browser session.
Description
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php.
Exploits (1)
The exploit describes a cross-site scripting (XSS) vulnerability in Tutos' file_select.php script due to improper input handling. An attacker can inject hostile code via the 'msg' parameter to execute arbitrary JavaScript in the context of a user's browser session.