CVE-2008-2123
SAP Internet Transaction Server 6.20 - Cross-Site Scripting via WGate ~service Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-2123. PoCs published by Portcullis.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in SAP Internet Transaction Server by injecting arbitrary JavaScript code via a malformed URL parameter. The vulnerability arises due to insufficient input sanitization in the '~service' parameter.
Description
Cross-site scripting (XSS) vulnerability in WGate in SAP Internet Transaction Server (ITS) 6.20 allows remote attackers to inject arbitrary web script or HTML via (1) a "<>" sequence in the ~service parameter to wgate.dll, or (2) Javascript splicing in the query string, a different vector than CVE-2006-5114.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in SAP Internet Transaction Server by injecting arbitrary JavaScript code via a malformed URL parameter. The vulnerability arises due to insufficient input sanitization in the '~service' parameter.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in SAP Internet Transaction Server by injecting arbitrary JavaScript code via unsanitized user input in the URL path. The PoC triggers an alert dialog, proving the vulnerability.