Exploitation Summary
EIP tracks 3 public exploits for CVE-2007-4115. PoCs published by Aria-Security Team.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in IT!CMS 0.2, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject malicious script code via the 'wndtitle' parameter.
Description
Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web script or HTML via the wndtitle parameter to (1) lang-en.php, (2) menu-ed.php, or (3) titletext-ed.php.
Exploits (3)
The provided text describes a cross-site scripting (XSS) vulnerability in IT!CMS 0.2, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject malicious script code via the 'wndtitle' parameter.
The provided text describes a cross-site scripting (XSS) vulnerability in IT!CMS 0.2, where user-supplied input is not properly sanitized. The example demonstrates how an attacker could inject malicious script code via the 'wndtitle' parameter in the 'menu-ed.php' file.
The provided text describes a cross-site scripting (XSS) vulnerability in IT!CMS 0.2, where user-supplied input is not properly sanitized. An example URL is given to demonstrate the vulnerability, but no actual exploit code is present.