Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-5411. PoCs published by Radu State.
AI-analyzed exploit summary This exploit demonstrates an HTML injection vulnerability in Linksys SPA941 devices by embedding a JavaScript alert in the 'From' field of a SIP INVITE message. The vulnerability arises due to insufficient input sanitization in the device's web interface, allowing arbitrary script execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in the Linksys SPA941 VoIP Phone with firmware 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the From header in a SIP message.
Exploits (1)
This exploit demonstrates an HTML injection vulnerability in Linksys SPA941 devices by embedding a JavaScript alert in the 'From' field of a SIP INVITE message. The vulnerability arises due to insufficient input sanitization in the device's web interface, allowing arbitrary script execution in the context of the affected site.