CVE-2007-3542
Pluxml 0.3.1 - Cross-Site Scripting via msg Parameter in admin/auth.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3542. PoCs published by DarkFig.
AI-analyzed exploit summary This exploit targets a remote code execution vulnerability in Pluxml 0.3.1 by leveraging an XSS flaw to steal admin session cookies and then uploading a malicious JPG file containing PHP shellcode. It establishes a reverse shell by binding to a specified IP and port.
Description
Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
Exploits (1)
This exploit targets a remote code execution vulnerability in Pluxml 0.3.1 by leveraging an XSS flaw to steal admin session cookies and then uploading a malicious JPG file containing PHP shellcode. It establishes a reverse shell by binding to a specified IP and port.