CVE-2007-6597
IPortalX < Build 033 - Cross-Site Scripting via KW, SF, or Date Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-6597. PoCs published by Doz.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in iPortalX by injecting a malicious script via the 'Date' parameter in the URL. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies or performing other malicious actions.
Description
Multiple cross-site scripting (XSS) vulnerabilities in IPortalX before Build 033 allow remote attackers to inject arbitrary web script or HTML via the (1) KW and (2) SF parameters to forum/login_user.asp, and (3) the Date parameter to blogs.asp.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in iPortalX by injecting a malicious script via the 'Date' parameter in the URL. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies or performing other malicious actions.
This exploit demonstrates a reflected XSS vulnerability in iPortalX by injecting malicious script tags into the 'Redirect' parameter of the login_user.asp page. The PoC shows how an attacker can execute arbitrary JavaScript in the context of the affected site.