CVE-2004-2564
Sambar Server 6.1 Beta 2 - Cross-Site Scripting via show.asp show Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2004-2564. PoCs published by Oliver Karow.
AI-analyzed exploit summary The provided text describes a vulnerability in Sambar Server 6.1 Beta 2, specifically an XSS issue in the 'showperf.asp' page. It notes that administrative privileges are required, but the default configuration lacks a password, making exploitation feasible.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in show.asp and (2) the title parameter in showperf.asp.
Exploits (2)
The provided text describes a vulnerability in Sambar Server 6.1 Beta 2, specifically an XSS issue in the 'showperf.asp' page. It notes that administrative privileges are required, but the default configuration lacks a password, making exploitation feasible.
The provided text describes multiple vulnerabilities in Sambar Server, including directory traversal and cross-site scripting (XSS). It includes a sample XSS payload but lacks executable exploit code.