CVE-2007-5954
MEDIUMJLMForo System - Cross-Site Scripting via buscador.php clave Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5954. PoCs published by Jose Luis Gongora Fernandez.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in JLMForo System, where the 'clave' parameter in 'buscador.php' is not properly sanitized. An attacker can exploit this by injecting arbitrary script code into the URL parameter.
Description
Cross-site scripting (XSS) vulnerability in buscador.php in JLMForo System allows remote attackers to inject arbitrary web script or HTML via the clave parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in JLMForo System, where the 'clave' parameter in 'buscador.php' is not properly sanitized. An attacker can exploit this by injecting arbitrary script code into the URL parameter.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N