CVE-2012-5702
dotproject < 2.1.7 - Cross-Site Scripting via Callback, Field, or Company Name Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-5702. PoCs published by High-Tech Bridge.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in Dotproject versions prior to 2.1.7. It includes proof-of-concept URLs that trigger JavaScript execution via injected scripts in various parameters.
Description
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to index.php. NOTE: the date parameter vector is already covered by CVE-2008-3886.
Exploits (1)
The exploit demonstrates multiple XSS vulnerabilities in Dotproject versions prior to 2.1.7. It includes proof-of-concept URLs that trigger JavaScript execution via injected scripts in various parameters.