CVE-2005-4574
CommonSpot Content Server <= 4.5 - Cross-Site Scripting via loader.cfm bNewWindow Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4574. PoCs published by r0t3d3Vil.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in PaperThin CommonSpot Content Server by injecting arbitrary script code via the 'errmsg' parameter in a URL. The vulnerability arises due to insufficient input sanitization, allowing execution of malicious scripts in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the bNewWindow parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in PaperThin CommonSpot Content Server by injecting arbitrary script code via the 'errmsg' parameter in a URL. The vulnerability arises due to insufficient input sanitization, allowing execution of malicious scripts in the context of the affected site.