CVE-2004-2702
Plesk 7.0 and 7.1 Reloaded - Cross-Site Scripting via login_name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2702. PoCs published by sourvivor.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Plesk Reloaded 7.1 by injecting malicious script code into the login_name parameter of the login_up.php3 page. The script executes in the context of the victim's browser, potentially stealing cookies or performing other malicious actions.
Description
Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Plesk Reloaded 7.1 by injecting malicious script code into the login_name parameter of the login_up.php3 page. The script executes in the context of the victim's browser, potentially stealing cookies or performing other malicious actions.