CVE-2012-1935
Newscoop 3.5.x < 3.5.5 and 4.x < 4 RC4 - Cross-Site Scripting via Back Parameter or Token/Email Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-1935. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This advisory details multiple vulnerabilities in Newscoop, including Remote File Inclusion (RFI), SQL Injection (SQLi), and Cross-Site Scripting (XSS). It provides Proof-of-Concept (PoC) URLs for each vulnerability but does not include executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4.x before 4 RC4 allow remote attackers to inject arbitrary web script or HTML via the (1) Back parameter to admin/ad.php, or the (2) token or (3) f_email parameter to admin/password_check_token.php.
Exploits (1)
This advisory details multiple vulnerabilities in Newscoop, including Remote File Inclusion (RFI), SQL Injection (SQLi), and Cross-Site Scripting (XSS). It provides Proof-of-Concept (PoC) URLs for each vulnerability but does not include executable exploit code.