CVE-2010-1905
Consona Live Assistance, Dynamic Agent, and Subscriber Assistance - Cross-Site Scripting via backurl Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1905. PoCs published by Ruben Santamarta.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in multiple Consona products by injecting malicious JavaScript via the 'backurl' parameter in 'n6plugindestructor.asp'. The payload executes arbitrary script code in the context of the affected site, potentially stealing authentication credentials.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allow remote attackers to inject arbitrary web script or HTML via crafted input to ASP pages, as demonstrated using the backurl parameter to sdccommon/verify/asp/n6plugindestructor.asp.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in multiple Consona products by injecting malicious JavaScript via the 'backurl' parameter in 'n6plugindestructor.asp'. The payload executes arbitrary script code in the context of the affected site, potentially stealing authentication credentials.