CVE-2007-3170
Uebimiau Webmail - Cross-Site Scripting via PATH_INFO or selected_theme Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3170. PoCs published by Michal Majchrowicz.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Uebimiau versions 2.7.2 and 2.7.10, where the 'selected_theme' parameter in error.php is not properly sanitized, allowing arbitrary JavaScript execution.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Uebimiau Webmail allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to redirect.php or (2) the selected_theme parameter to demo/pop3/error.php.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in Uebimiau versions 2.7.2 and 2.7.10, where the 'selected_theme' parameter in error.php is not properly sanitized, allowing arbitrary JavaScript execution.