CVE-2008-1510
Alkacon OpenCMS 7.0.3 - Cross-Site Scripting via User List Search Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1510. PoCs published by nnposter.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Alkacon OpenCms 7.0.3 by injecting malicious script tags into the 'searchfilter' and 'listSearchFilter' parameters. The payload triggers an alert with the user's cookies, proving arbitrary JavaScript execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in system/workplace/admin/accounts/users_list.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the (1) searchfilter or (2) listSearchFilter parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Alkacon OpenCms 7.0.3 by injecting malicious script tags into the 'searchfilter' and 'listSearchFilter' parameters. The payload triggers an alert with the user's cookies, proving arbitrary JavaScript execution in the context of the affected site.