CVE-2007-3991
Asp cvmatik < 1.1 - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3991. PoCs published by GeFORC3.
AI-analyzed exploit summary This exploit demonstrates multiple HTML injection vulnerabilities in Asp cvmatik 1.1 due to insufficient input sanitization. Attackers can inject arbitrary HTML/script code into input fields, leading to XSS attacks.
Description
Multiple cross-site scripting (XSS) vulnerabilities in cv.asp in Asp cvmatik 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz (Ady), (2) Soyadiniz (Soyady), (3) Ehliyet, (4) Askerlik, and (5) GSM parameters; and possibly other unspecified vectors.
Exploits (1)
This exploit demonstrates multiple HTML injection vulnerabilities in Asp cvmatik 1.1 due to insufficient input sanitization. Attackers can inject arbitrary HTML/script code into input fields, leading to XSS attacks.