CVE-2010-4275
Radius Manager 3.8.0 - Authenticated Cross-Site Scripting via Name or Descr Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2010-4275. PoCs published by Rodrigo Rubira Branco.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in Radius Manager 3.6.0 by injecting malicious scripts into the 'name' and 'descr' parameters of admin.php endpoints. The PoC includes HTTP requests with payloads that trigger JavaScript alerts, confirming the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) name or (2) descr parameter in an (a) update_usergroup or a (b) store_nas action to admin.php.
Exploits (2)
This exploit demonstrates multiple XSS vulnerabilities in Radius Manager 3.6.0 by injecting malicious scripts into the 'name' and 'descr' parameters of admin.php endpoints. The PoC includes HTTP requests with payloads that trigger JavaScript alerts, confirming the vulnerability.
This is a detailed writeup describing multiple stored XSS vulnerabilities in Radius Manager 3.8.0, where input fields like 'Group Name' and 'Description' fail to sanitize user input, allowing attackers to inject malicious JavaScript.