CVE-2003-0749
SAP Internet Transaction Server 4620.2.0.323011 - Cross-Site Scripting via ~service Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-0749. PoCs published by Martin Eiszner.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in SAP Internet Transaction Server's 'wgate.dll' component. The vulnerability arises from insufficient sanitization of user-supplied input, allowing arbitrary JavaScript execution.
Description
Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in SAP Internet Transaction Server's 'wgate.dll' component. The vulnerability arises from insufficient sanitization of user-supplied input, allowing arbitrary JavaScript execution.