CVE-2013-2623
MEDIUMtelaen < 1.3.1 - Cross-Site Scripting via f_email Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-2623. PoCs published by Manuel García Cárdenas.
AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in Telaen versions prior to 1.3.1 by injecting a malicious script via the 'f_email' parameter. The payload executes arbitrary JavaScript in the context of the affected site.
Description
Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the "f_email" parameter in index.php.
Exploits (1)
The exploit demonstrates a reflected XSS vulnerability in Telaen versions prior to 1.3.1 by injecting a malicious script via the 'f_email' parameter. The payload executes arbitrary JavaScript in the context of the affected site.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N