CVE-2008-1045
Alkacon OpenCMS 7.0.3 - Cross-Site Scripting via File Tree Navigation Resource Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1045. PoCs published by nnposter.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Alkacon OpenCms by injecting arbitrary JavaScript code via the 'resource' parameter in the URL. The PoC uses an alert box to display the user's cookies, proving the vulnerability.
Description
Cross-site scripting (XSS) vulnerability in the file tree navigation function in system/workplace/views/explorer/tree_files.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the resource parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Alkacon OpenCms by injecting arbitrary JavaScript code via the 'resource' parameter in the URL. The PoC uses an alert box to display the user's cookies, proving the vulnerability.