CVE-2008-1225
WebCT Campus Edition 4.1.5.8 - Authenticated Cross-Site Scripting via Mail or Discussion Board Message
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1225. PoCs published by Lupton.
AI-analyzed exploit summary This exploit demonstrates an HTML injection vulnerability in WebCT 4.1.5.8, allowing attackers to steal session cookies via JavaScript injection in mail or discussion board messages. The PoC includes two attacks: one for IE6SP2 (automatic) and another for Firefox (manual).
Description
Multiple cross-site scripting (XSS) vulnerabilities in WebCT Campus Edition 4.1.5.8, when "Don't wrap text" is enabled, allow remote authenticated users to inject arbitrary web script or HTML via a (1) mail message or (2) discussion board message. NOTE: this might overlap CVE-2005-1076.
Exploits (1)
This exploit demonstrates an HTML injection vulnerability in WebCT 4.1.5.8, allowing attackers to steal session cookies via JavaScript injection in mail or discussion board messages. The PoC includes two attacks: one for IE6SP2 (automatic) and another for Firefox (manual).