CVE-2004-2246
Goollery - Cross-Site Scripting via Conversation ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2246. PoCs published by Lostmon.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Goollery, where the 'page' parameter in several scripts fails to sanitize user-supplied input. An example URI is given to demonstrate how an attacker could craft a malicious link to render hostile HTML and script code in a victim's browser.
Description
Cross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or web script via the conversation_id parameter to viewpic.php.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in Goollery, where the 'page' parameter in several scripts fails to sanitize user-supplied input. An example URI is given to demonstrate how an attacker could craft a malicious link to render hostile HTML and script code in a victim's browser.