CVE-2005-3285
Comersus BackOffice Plus - Cross-Site Scripting via forwardTo1, forwardTo2, nameFT1, or nameFT2 Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3285. PoCs published by Lostmon.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in BackOffice Plus, detailing how unsanitized user input can lead to arbitrary script execution in a user's browser context. It includes an example URL demonstrating the vulnerability but lacks executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows remote attackers to inject arbitrary web script or HTML via the (1) forwardTo1, (2) forwardTo2, (3) nameFT1, or (4) nameFT2 parameters.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in BackOffice Plus, detailing how unsanitized user input can lead to arbitrary script execution in a user's browser context. It includes an example URL demonstrating the vulnerability but lacks executable exploit code.