CVE-2010-0641
Cisco Collaboration Server 5 - Cross-Site Scripting via LoginPage.jhtml Dest Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-0641. PoCs published by s4squatch.
AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability and a Java Servlet source code disclosure flaw in Cisco Collaboration Server 5. The XSS is triggered via a crafted URL parameter, while the source code disclosure is achieved through URL encoding bypasses.
Description
Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5 allows remote attackers to inject arbitrary web script or HTML via the dest parameter.
Exploits (1)
The exploit demonstrates a reflected XSS vulnerability and a Java Servlet source code disclosure flaw in Cisco Collaboration Server 5. The XSS is triggered via a crafted URL parameter, while the source code disclosure is achieved through URL encoding bypasses.