CVE-2005-3128
EXPLOITED NUCLEIAddress Add Plugin 1.9 and 2.0 for Squirrelmail - Cross-Site Scripting via IMG Tag
Title source: llmExploitation Summary
CVE-2005-3128 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including anonymous. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in the SquirrelMail Address Add Plugin by injecting malicious JavaScript via the 'first' parameter in the URL. The PoC triggers an alert dialog when the mouse hovers over the manipulated text.
Description
Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote attackers to inject arbitrary web script or HTML via the IMG tag.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in the SquirrelMail Address Add Plugin by injecting malicious JavaScript via the 'first' parameter in the URL. The PoC triggers an alert dialog when the mouse hovers over the manipulated text.