CVE-2007-3014
activeWeb contentserver < 5.6.2964 - Cross-Site Scripting via msg Parameter or MIME Type
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-3014. PoCs published by RedTeam Pentesting.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in activeWeb contentserver versions prior to 5.6.2964. It includes a proof-of-concept URL demonstrating the vulnerability but lacks executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) errors/rights.asp or (2) errors/transaction.asp, or (3) the name of a MIME type (mimetype).
Exploits (2)
The provided text describes a cross-site scripting (XSS) vulnerability in activeWeb contentserver versions prior to 5.6.2964. It includes a proof-of-concept URL demonstrating the vulnerability but lacks executable exploit code.
The provided code is a writeup describing a cross-site scripting (XSS) vulnerability in activeWeb contentserver. It includes a proof-of-concept URL demonstrating the XSS issue.