CVE-2008-6637
SAFARI Montage < 3.1.3 - Cross-Site Scripting via School and Email Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6637. PoCs published by Omer Singer.
AI-analyzed exploit summary This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in SAFARI Montage 3.1.3 by injecting arbitrary script code via the 'school' and 'email' parameters in the forgotPW.php page. The PoC includes examples of both reflected XSS and HTML injection.
Description
Multiple cross-site scripting (XSS) vulnerabilities in forgotPW.php in Library Video Company SAFARI Montage 3.1.x allow remote attackers to inject arbitrary web script or HTML via the (1) school and (2) email parameters.
Exploits (1)
This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in SAFARI Montage 3.1.3 by injecting arbitrary script code via the 'school' and 'email' parameters in the forgotPW.php page. The PoC includes examples of both reflected XSS and HTML injection.