CVE-2004-2574
phpGroupWare < 0.9.16.005 - Cross-Site Scripting via Date Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2574. PoCs published by Cedric Cochin.
AI-analyzed exploit summary This exploit demonstrates an HTML injection vulnerability in PhpGroupWare, allowing an attacker to inject arbitrary HTML and script code via the 'date' parameter. The provided payload triggers a JavaScript alert with the user's cookies, confirming the vulnerability.
Description
Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web script or HTML via the date parameter in a calendar.uicalendar.planner menuaction.
Exploits (1)
This exploit demonstrates an HTML injection vulnerability in PhpGroupWare, allowing an attacker to inject arbitrary HTML and script code via the 'date' parameter. The provided payload triggers a JavaScript alert with the user's cookies, confirming the vulnerability.