CVE-2004-0678
12Planet Chat Server 2.9 - Cross-Site Scripting via Page Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-0678. PoCs published by Donato Ferrante.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in 12Planet Chat Server version 2.9, where user-supplied input is not properly sanitized, allowing arbitrary script execution in the context of the web server.
Description
Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other users via the page parameter.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in 12Planet Chat Server version 2.9, where user-supplied input is not properly sanitized, allowing arbitrary script execution in the context of the web server.