CVE-2007-3613
SAP Internet Graphics Server - Cross-Site Scripting via ADM:GETLOGFILE PARAMS Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3613. PoCs published by Mark Litchfield.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in SAP Internet Graphics Server by injecting a script tag into the PARAMS parameter of the ADM:GETLOGFILE endpoint. The vulnerability arises due to insufficient input sanitization, allowing arbitrary JavaScript execution in the context of the affected website.
Description
Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in SAP Internet Graphics Server by injecting a script tag into the PARAMS parameter of the ADM:GETLOGFILE endpoint. The vulnerability arises due to insufficient input sanitization, allowing arbitrary JavaScript execution in the context of the affected website.