CVE-2008-3161
IBM Maximo 4.1 and 5.2 - Cross-Site Scripting via HTTP Headers
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3161. PoCs published by Deniz Cevik.
AI-analyzed exploit summary This exploit demonstrates an XSS vulnerability in IBM Maximo by injecting malicious scripts into HTTP headers. The PoC shows how arbitrary script code can be executed in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in jsp/common/system/debug.jsp in IBM Maximo 4.1 and 5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Accept, (2) Accept-Language, (3) UA-CPU, (4) Accept-Encoding, (5) User-Agent, or (6) Cookie HTTP header. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates an XSS vulnerability in IBM Maximo by injecting malicious scripts into HTTP headers. The PoC shows how arbitrary script code can be executed in the context of the affected site.