CVE-2010-3314
EGroupware 1.4.001+.002 1.6.001+.002 - Cross-Site Scripting via lang Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-3314. PoCs published by Nahuel Grisolia.
AI-analyzed exploit summary The document describes a remote command execution (RCE) vulnerability in EGroupware due to insufficient input sanitization in the `aspell_path` parameter of `spellchecker.php`. It also includes a reflected XSS vulnerability in the `lang` parameter of `login.php`.
Description
Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Exploits (1)
The document describes a remote command execution (RCE) vulnerability in EGroupware due to insufficient input sanitization in the `aspell_path` parameter of `spellchecker.php`. It also includes a reflected XSS vulnerability in the `lang` parameter of `login.php`.