CVE-2008-6404
eXtrovert Software Thyme 1.3 - Cross-Site Scripting via Callback Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6404. PoCs published by DigiTrust Group.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Thyme 1.3 by injecting malicious JavaScript code via the 'callback' parameter in the 'add_calendars.php' script. The payload triggers an alert displaying the user's cookies, proving arbitrary script execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in add_calendars.php in eXtrovert Software Thyme 1.3 allows remote attackers to inject arbitrary web script or HTML via the callback parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Thyme 1.3 by injecting malicious JavaScript code via the 'callback' parameter in the 'add_calendars.php' script. The payload triggers an alert displaying the user's cookies, proving arbitrary script execution in the context of the affected site.