CVE-2007-5455
WWWISIS 7.1 - Cross-Site Scripting via IsisScript lang or exprSearch Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5455. PoCs published by JosS.
AI-analyzed exploit summary The exploit demonstrates a local file disclosure vulnerability and XSS in WWWISIS (Search) by manipulating the IsisScript parameter. It provides direct URLs to exploit these vulnerabilities without requiring authentication.
Description
Cross-site scripting (XSS) vulnerability in wxis.exe in WWWISIS 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a call to the iah/iah.xis IsisScript code, possibly involving the lang or exprSearch parameter.
Exploits (1)
The exploit demonstrates a local file disclosure vulnerability and XSS in WWWISIS (Search) by manipulating the IsisScript parameter. It provides direct URLs to exploit these vulnerabilities without requiring authentication.