Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-4400. PoCs published by r0t3d3Vil.
AI-analyzed exploit summary The provided text describes multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal Enterprise version 3.6.1. It includes example URLs demonstrating how unsanitized input in specific parameters can lead to arbitrary script execution in a user's browser context.
Description
Cross-site scripting (XSS) vulnerability in downloads/portal_ent in Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) _77_struts_action, (2) p_p_mode, and (3) p_p_state parameters.
Exploits (1)
The provided text describes multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal Enterprise version 3.6.1. It includes example URLs demonstrating how unsanitized input in specific parameters can lead to arbitrary script execution in a user's browser context.