CVE-2004-1935
SCT Campus Pipeline - Stored Cross-Site Scripting via Email Attachment Event Handlers
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1935. PoCs published by spiffomatic 64.
AI-analyzed exploit summary The exploit demonstrates an XSS vulnerability in Campus Pipeline's email system, allowing script injection via malicious HTML in email attachments. It includes examples for deleting messages, composing new emails, and site redirection.
Description
Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload, onmouseover, and other Javascript events in an e-mail attachment.
Exploits (1)
The exploit demonstrates an XSS vulnerability in Campus Pipeline's email system, allowing script injection via malicious HTML in email attachments. It includes examples for deleting messages, composing new emails, and site redirection.