CVE-2010-2265
Windows XP and Server 2003 - Cross-Site Scripting via Help and Support Center svr Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2265. PoCs published by Tavis Ormandy.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Microsoft Windows Help and Support Center. The vulnerability allows arbitrary script execution in the browser's privileged zone by injecting malicious input into the URI.
Description
Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm. NOTE: this can be leveraged with CVE-2010-1885 to execute arbitrary commands without user interaction.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Microsoft Windows Help and Support Center. The vulnerability allows arbitrary script execution in the browser's privileged zone by injecting malicious input into the URI.