CVE-2004-1911
AzDGDatingLite 2.1.1 - Cross-Site Scripting via Language Parameter or ID Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2004-1911. PoCs published by Janek Vind.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1, where malicious script code can be injected via the 'view.php' URL parameter. The example demonstrates stealing cookie-based authentication credentials through a crafted link.
Description
Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) l parameter (aka language variable) to index.php or (2) id parameter to view.php.
Exploits (2)
The provided text describes a cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1, where malicious script code can be injected via the 'view.php' URL parameter. The example demonstrates stealing cookie-based authentication credentials through a crafted link.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 by injecting a malicious script via the 'l' parameter in the URL. The script executes arbitrary JavaScript, potentially stealing cookie-based authentication credentials.