CVE-2004-1797
FreznoShop <= 1.3.0 RC1 - Cross-Site Scripting via Search Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1797. PoCs published by David S. Ferreira.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in FreznoShop, where malicious script code can be injected via the search parameter. The example demonstrates a basic XSS payload that triggers an alert with the document domain.
Description
Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in FreznoShop, where malicious script code can be injected via the search parameter. The example demonstrates a basic XSS payload that triggers an alert with the document domain.