CVE-2012-4266
Proman Xpress 5.0.1 - Cross-Site Scripting via cl_comments Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-4266. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary The document describes multiple web vulnerabilities in Proman Xpress v5.0.1, including SQL injection and persistent XSS. It provides proof-of-concept details for exploitation but lacks executable code.
Description
Cross-site scripting (XSS) vulnerability in client_details.php in Proman Xpress 5.0.1 allows remote attackers to inject arbitrary web script or HTML via the cl_comments parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
The document describes multiple web vulnerabilities in Proman Xpress v5.0.1, including SQL injection and persistent XSS. It provides proof-of-concept details for exploitation but lacks executable code.