20040824 XSS in Plesk 7.1 Reloadedmailing list
http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1022.html CVE-2004-2702
SWsoft Plesk Reloaded 7.1 - 'Login_name' Cross-Site Scripting
Record summary
CVE-2004-2702 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSWsoft Plesk Reloaded 7.1 - 'Login_name' Cross-Site ScriptingExploitDB exploitby sourvivorNot analyzed1 file
References
920040824 Re: [Full-Disclosure] XSS in Plesk 7.1 Reloadedmailing list
http://archives.neohapsis.com/archives/fulldisclosure/2004-08/1031.html 20041223 Plesk 7 Cross-Site Scriptingmailing list
http://archives.neohapsis.com/archives/fulldisclosure/2004-12/0554.html 12368Third-party advisory
http://secunia.com/advisories/12368 1011042vdb entry
http://securitytracker.com/id?1011042 9149vdb entry
http://www.osvdb.org/9149 11024vdb entry
http://www.securityfocus.com/bid/11024 plesk-loginname-xss(17085)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/17085 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2702