Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2887. PoCs published by vagrant.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in WÃYS 1.0 by injecting a malicious script via the 'Page' and 'No' parameters in the URL. The script executes in the context of the affected website, potentially allowing cookie theft or other client-side attacks.
Description
Cross-site scripting (XSS) vulnerability in index.php in Web Icerik Yonetim Sistemi (WIYS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the No parameter in the Sayfa page.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in WÃYS 1.0 by injecting a malicious script via the 'Page' and 'No' parameters in the URL. The script executes in the context of the affected website, potentially allowing cookie theft or other client-side attacks.