Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-2941. PoCs published by MustLive.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Yandex.Server by injecting a malicious script via the 'text' parameter in the search URL. The PoC uses a simple alert to display the document cookie, proving arbitrary JavaScript execution.
Description
Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server 2010 9.0 Enterprise allows remote attackers to inject arbitrary web script or HTML via the text parameter.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Yandex.Server by injecting a malicious script via the 'text' parameter in the search URL. The PoC uses a simple alert to display the document cookie, proving arbitrary JavaScript execution.