CVE-2008-1229
JSPWiki 2.4.104 and 2.5.139 - Cross-Site Scripting via Editor Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1229. PoCs published by BugSec LTD.
AI-analyzed exploit summary The document describes multiple vulnerabilities in JSPWiki, including a local .jsp file inclusion vulnerability and a cross-site scripting (XSS) vulnerability. It provides technical details on how these vulnerabilities can be exploited to disclose sensitive information or execute arbitrary script code.
Description
Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject arbitrary web script or HTML via the editor parameter, a different vector than CVE-2007-5120.b.
Exploits (1)
The document describes multiple vulnerabilities in JSPWiki, including a local .jsp file inclusion vulnerability and a cross-site scripting (XSS) vulnerability. It provides technical details on how these vulnerabilities can be exploited to disclose sensitive information or execute arbitrary script code.