CVE-2007-5127
SimpGB 1.46.02 - Cross-Site Scripting via l_username or l_emoticonlist Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-5127. PoCs published by netVigilance.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in SimpGB 1.46.02 by injecting arbitrary JavaScript code via the 'l_emoticonlist' parameter in the admin/emoticonlist.php file. The PoC uses a simple alert to display the document cookies, proving the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in SimpGB 1.46.02 allow remote attackers to inject arbitrary web script or HTML via (1) the l_username parameter to the default URI under admin/ or (2) the l_emoticonlist parameter to admin/emoticonlist.php.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in SimpGB 1.46.02 by injecting arbitrary JavaScript code via the 'l_emoticonlist' parameter in the admin/emoticonlist.php file. The PoC uses a simple alert to display the document cookies, proving the vulnerability.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in SimpGB 1.46.02 by injecting arbitrary JavaScript code via the 'l_username' parameter. The PoC triggers an alert box displaying the document cookies, proving the vulnerability.