CVE-2008-7043
FreshScripts Fresh Email Script 1.0-1.11 - Cross-Site Scripting via Email Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7043. PoCs published by Don.
AI-analyzed exploit summary This is a vulnerability writeup for CVE-2008-7043, detailing file inclusion and cookie manipulation vulnerabilities in Fresh Email Script versions 1.0 to 1.11. It describes the attack vectors but does not include executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in register.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to inject arbitrary web script or HTML via the Email parameter. NOTE: this can be leveraged to modify cookies and conduct session fixation attacks.
Exploits (1)
This is a vulnerability writeup for CVE-2008-7043, detailing file inclusion and cookie manipulation vulnerabilities in Fresh Email Script versions 1.0 to 1.11. It describes the attack vectors but does not include executable exploit code.