CVE-2007-1240
Docebo CMS 3.0.3-3.0.5 - Cross-Site Scripting via Searchkey or Chat Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-1240. PoCs published by r00t.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Docebo CMS versions 3.0.5 and prior. It includes a proof-of-concept URL demonstrating the vulnerability but lacks executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the searchkey parameter to index.php, or the (2) sn or (3) ri parameter to modules/htmlframechat/index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (2)
The provided text describes a cross-site scripting (XSS) vulnerability in Docebo CMS versions 3.0.5 and prior. It includes a proof-of-concept URL demonstrating the vulnerability but lacks executable exploit code.
The provided text describes a cross-site scripting (XSS) vulnerability in Docebo 3.0.5 and prior versions. It includes example URLs demonstrating the vulnerability but does not contain executable exploit code.