CVE-2015-4665
Xceedium Xsuite <= 2.4.4.1 - Cross-Site Scripting via ajax_cmd.php fileName Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-4665. PoCs published by modzero.
AI-analyzed exploit summary This is a detailed security advisory describing multiple vulnerabilities in Xceedium Xsuite, including command injection, XSS, directory traversal, privilege escalation, and hard-coded credentials. It provides proof-of-concept HTTP requests and code snippets to demonstrate the vulnerabilities.
Description
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName parameter.
Exploits (1)
This is a detailed security advisory describing multiple vulnerabilities in Xceedium Xsuite, including command injection, XSS, directory traversal, privilege escalation, and hard-coded credentials. It provides proof-of-concept HTTP requests and code snippets to demonstrate the vulnerabilities.