CVE-2008-2398
EXPLOITED NUCLEIAppServ < 2.5.10 - Cross-Site Scripting via appservlang Parameter
Title source: llmExploitation Summary
CVE-2008-2398 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including CWH Underground. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in AppServ Open Project 2.5.10. The vulnerability arises from improper sanitization of the 'appservlang' parameter, allowing arbitrary JavaScript execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in index.php in AppServ Open Project 2.5.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the appservlang parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in AppServ Open Project 2.5.10. The vulnerability arises from improper sanitization of the 'appservlang' parameter, allowing arbitrary JavaScript execution in the context of the affected site.