Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-1095. PoCs published by snakespc.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in TRUC 0.11.0 by injecting a malicious script via the 'error' parameter in the password reset page. The script executes in the context of the affected site, potentially stealing cookies.
Description
Cross-site scripting (XSS) vulnerability in login_reset_password_page.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in TRUC 0.11.0 by injecting a malicious script via the 'error' parameter in the password reset page. The script executes in the context of the affected site, potentially stealing cookies.