CVE-2007-0144
Digitizing Quote And Ordering System 1.0 - Authenticated Cross-Site Scripting via search.asp ordernum Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0144. PoCs published by ajann.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in QUOTE&ORDERING SYSTEM 1.0 via the 'ordernum' parameter in search.asp. It includes functional payloads for both vulnerabilities, requiring prior authentication.
Description
Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parameter.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in QUOTE&ORDERING SYSTEM 1.0 via the 'ordernum' parameter in search.asp. It includes functional payloads for both vulnerabilities, requiring prior authentication.