Exploitation Summary
EIP tracks 1 public exploit for CVE-2011-1524. PoCs published by Nikolas Sotiriu.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Symantec LiveUpdate Administrator, allowing an attacker to inject HTML/JavaScript or add an admin user via a crafted payload. The script sets up a local server to serve malicious HTML when the victim accesses a specific URL.
Description
Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to inject arbitrary web script or HTML via the username field, as demonstrated by injecting an IFRAME element into the event log, a different vulnerability than CVE-2011-0545.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in Symantec LiveUpdate Administrator, allowing an attacker to inject HTML/JavaScript or add an admin user via a crafted payload. The script sets up a local server to serve malicious HTML when the victim accesses a specific URL.