CVE-2012-3840
MyClientBase 0.12 - Cross-Site Scripting via First Name or Last Name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-3840. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary The document describes multiple SQL injection vulnerabilities in MyClientBase v0.12, specifically in the invoice and tag search functionality. It includes error logs and details of the exploitation technique but does not contain executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php/users/form/user_id in MyClientBase 0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name or (2) last_name parameters.
Exploits (1)
The document describes multiple SQL injection vulnerabilities in MyClientBase v0.12, specifically in the invoice and tag search functionality. It includes error logs and details of the exploitation technique but does not contain executable exploit code.