CVE-2007-3838
TBDev.NET DR 11-10-05-BETA-SF1:111005 - Cross-Site Scripting via Avatar Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3838. PoCs published by PescaoDeth.
AI-analyzed exploit summary This is a writeup describing an HTML injection vulnerability in TBDev.NET DR. The vulnerability allows an attacker to inject malicious JavaScript code via the 'avatar' POST parameter, leading to potential cookie theft or other client-side attacks.
Description
Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 11-10-05-BETA-SF1:111005 and earlier allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the avatar parameter. NOTE: this may be related to the tracker program in the Janitor package. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This is a writeup describing an HTML injection vulnerability in TBDev.NET DR. The vulnerability allows an attacker to inject malicious JavaScript code via the 'avatar' POST parameter, leading to potential cookie theft or other client-side attacks.