CVE-2017-12971
MEDIUMApache2Triad 1.5.4 - Cross-Site Scripting via phpsftpd/users.php Account Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-12971. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates session fixation, CSRF, and persistent XSS vulnerabilities in Apache2Triad v1.5.4. It includes PoC code for each CVE, showing how an attacker can hijack sessions, execute unauthorized actions, and inject malicious scripts.
Description
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account parameter to phpsftpd/users.php.
Exploits (1)
This exploit demonstrates session fixation, CSRF, and persistent XSS vulnerabilities in Apache2Triad v1.5.4. It includes PoC code for each CVE, showing how an attacker can hijack sessions, execute unauthorized actions, and inject malicious scripts.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N