CVE-2004-2072
Mambo Open Source 4.6 - Cross-Site Scripting via Itemid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2072. PoCs published by David Sopas Ferreira.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Mambo Open Source by injecting a script tag into the 'Itemid' parameter of the 'index.php' script. The PoC uses a simple alert to confirm the vulnerability.
Description
Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Mambo Open Source by injecting a script tag into the 'Itemid' parameter of the 'index.php' script. The PoC uses a simple alert to confirm the vulnerability.