CVE-2017-16841
MEDIUMLanSweeper < 6.0.100.94 - Cross-Site Scripting via Calendar Description Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-16841. PoCs published by Miguel Mendez Z.
AI-analyzed exploit summary The provided text describes a Cross-Site Scripting (XSS) vulnerability in LanSweeper 6.0.100.75, specifically via the 'description' parameter in '/Calendar/CalendarActions.aspx'. It includes vulnerable URLs and references a proof-of-concept video but lacks actual exploit code.
Description
LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx.
Exploits (1)
The provided text describes a Cross-Site Scripting (XSS) vulnerability in LanSweeper 6.0.100.75, specifically via the 'description' parameter in '/Calendar/CalendarActions.aspx'. It includes vulnerable URLs and references a proof-of-concept video but lacks actual exploit code.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N