CVE-2013-6042
Webuzo < 2.1.4 - Cross-Site Scripting via File Manager Login User Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-6042.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Webuzo 2.1.3, including remote OS command injection via cookie manipulation, reflected XSS in the File Manager module, and username enumeration. The PoC includes HTTP requests with payloads for each vulnerability.
Description
Cross-site scripting (XSS) vulnerability in filemanager/login.php in the File Manager module in Softaculous Webuzo before 2.1.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Webuzo 2.1.3, including remote OS command injection via cookie manipulation, reflected XSS in the File Manager module, and username enumeration. The PoC includes HTTP requests with payloads for each vulnerability.