CVE-2005-4576
Fatwire UpdateEngine < 6.2 - Cross-Site Scripting via COUNTRYNAME, EMAIL, or FUELAP_TEMPLATENAME Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4576. PoCs published by r0t3d3Vil.
AI-analyzed exploit summary The provided text describes multiple XSS vulnerabilities in FatWire UpdateEngine, with example URLs demonstrating how arbitrary script code can be injected via parameters like FUELAP_TEMPLATENAME and EMAIL. No actual exploit code is present, only documentation of the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) COUNTRYNAME, (2) EMAIL, and (3) FUELAP_TEMPLATENAME parameters.
Exploits (1)
The provided text describes multiple XSS vulnerabilities in FatWire UpdateEngine, with example URLs demonstrating how arbitrary script code can be injected via parameters like FUELAP_TEMPLATENAME and EMAIL. No actual exploit code is present, only documentation of the vulnerability.