CVE-2004-2725
Aztek Forum 4.0 - Cross-Site Scripting via Search, Email, Return, and Title Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2725. PoCs published by benji lemien.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Aztek Forum by injecting malicious JavaScript via the 'return' parameter in the URL. The script steals the user's cookie and redirects it to an attacker-controlled server.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in (a) search.php, (2) the email parameter in (b) subscribe.php, and (3) the return and (4) title parameters in (c) forum_2.php.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Aztek Forum by injecting malicious JavaScript via the 'return' parameter in the URL. The script steals the user's cookie and redirects it to an attacker-controlled server.