CVE-2008-0540
trixbox 2.4.2.0 - Cross-Site Scripting via User or Maintenance Index Query String
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-0540. PoCs published by Omer Singer.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in trixbox 2.4.2.0 by injecting a script tag into the URL parameter of the maint/index.php page. The PoC triggers an alert dialog, confirming the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web script or HTML via the query string to index.php in (1) user/ or (2) maint/.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in trixbox 2.4.2.0 by injecting a script tag into the URL parameter of the maint/index.php page. The PoC triggers an alert dialog, confirming the vulnerability.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in trixbox 2.4.2.0 by injecting a script tag into the URL parameter of the user/index.php page. The PoC triggers an alert dialog, confirming the vulnerability.