CVE-2007-5649
SocketMail 2.2.1 - Cross-Site Scripting via lostpwd.php lost_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5649. PoCs published by Ivan Sanchez.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in SocketMail, where insufficient input sanitization allows arbitrary script execution in a user's browser context. The example URL demonstrates the vulnerability by injecting malicious input via the 'lost_id' parameter.
Description
Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in SocketMail, where insufficient input sanitization allows arbitrary script execution in a user's browser context. The example URL demonstrates the vulnerability by injecting malicious input via the 'lost_id' parameter.