CVE-2004-2128
BRS WebWeaver 1.07 - Cross-Site Scripting via ISAPISkeleton.dll Query String
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2128. PoCs published by Oliver Karow.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07, where an attacker can inject malicious script code via a crafted URL. The example demonstrates a basic XSS payload using an alert dialog.
Description
Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07, where an attacker can inject malicious script code via a crafted URL. The example demonstrates a basic XSS payload using an alert dialog.