CVE-2004-2096
mephistoles_httpd 0.6.0 final - Cross-Site Scripting via URL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2096. PoCs published by Donato Ferrante.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in Mephistoles 'httpd' daemon by injecting a malicious script tag into the URL path. The server fails to sanitize user input, allowing arbitrary JavaScript execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0 final allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the URL.
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in Mephistoles 'httpd' daemon by injecting a malicious script tag into the URL path. The server fails to sanitize user input, allowing arbitrary JavaScript execution in the context of the affected site.