CVE-2005-1077
XAMPP 1.4.x - Cross-Site Scripting via cds.php, Guestbook-EN.pl, or phonebook.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-1077. PoCs published by Morning Wood.
AI-analyzed exploit summary The provided text describes an HTML injection vulnerability in XAMPP's phonebook.php, where user-supplied input is not properly sanitized. An attacker can exploit this to execute arbitrary script code in a user's browser.
Description
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php.
Exploits (1)
The provided text describes an HTML injection vulnerability in XAMPP's phonebook.php, where user-supplied input is not properly sanitized. An attacker can exploit this to execute arbitrary script code in a user's browser.