CVE-2004-2040
e107 0.615 - Cross-Site Scripting via Multiple Input Fields
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2004-2040. PoCs published by Janek Vind.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in e107, including XSS, HTML injection, file inclusion, and SQL injection. It includes a single example URL demonstrating an XSS vulnerability in the 'avmsg' parameter of usersettings.php.
Description
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg parameter to usersettings.php.
Exploits (2)
The provided text describes multiple vulnerabilities in e107, including XSS, HTML injection, file inclusion, and SQL injection. It includes a single example URL demonstrating an XSS vulnerability in the 'avmsg' parameter of usersettings.php.
This exploit demonstrates an HTML injection vulnerability in e107's 'email article to a friend' and 'submit news' pages, allowing arbitrary JavaScript execution via an XSS payload.