CVE-2007-1989
dotclear < 1.2.6 - Cross-Site Scripting via post_id or tool_url Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-1989. PoCs published by nassim.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in DotClear versions prior to 1.2.6. It explains the vulnerability and provides a sample exploit URL but does not include functional exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php. NOTE: some of these details are obtained from third party information.
Exploits (2)
The provided text describes a cross-site scripting (XSS) vulnerability in DotClear versions prior to 1.2.6. It explains the vulnerability and provides a sample exploit URL but does not include functional exploit code.
The provided text describes a cross-site scripting (XSS) vulnerability in DotClear versions prior to 1.2.6. It explains the issue and provides a sample URL demonstrating the vulnerability but does not include executable exploit code.