CVE-2004-2564

Sambar Server 6.1 Beta 2 - Cross-Site Scripting via show.asp show Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2004-2564. PoCs published by Oliver Karow.

AI-analyzed exploit summary The provided text describes a vulnerability in Sambar Server 6.1 Beta 2, specifically an XSS issue in the 'showperf.asp' page. It notes that administrative privileges are required, but the default configuration lacks a password, making exploitation feasible.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in show.asp and (2) the title parameter in showperf.asp.

Exploits (2)

exploitdb WRITEUP VERIFIED
by Oliver Karow · textremotewindows
https://www.exploit-db.com/exploits/24162

The provided text describes a vulnerability in Sambar Server 6.1 Beta 2, specifically an XSS issue in the 'showperf.asp' page. It notes that administrative privileges are required, but the default configuration lacks a password, making exploitation feasible.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Sambar Server 6.1 Beta 2
Auth required
Prerequisites: Administrative access (default configuration may lack password)
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Oliver Karow · textremotewindows
https://www.exploit-db.com/exploits/24161

The provided text describes multiple vulnerabilities in Sambar Server, including directory traversal and cross-site scripting (XSS). It includes a sample XSS payload but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: Sambar Server 6.1 Beta 2
Auth required
Prerequisites: Administrative access to the server · Default or weak administrative credentials
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11748
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/6584
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1010353
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10444
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16286
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/6583

Scores

EPSS 0.0473
EPSS Percentile 90.7%

Details

Status published
Products (1)
sambar/sambar_server 6.1 beta2
Published Dec 31, 2004
Tracked Since Feb 18, 2026