CVE-2017-6478
MEDIUM NUCLEImangoswebv4 < 4.0.8 - Reflected Cross-Site Scripting via Install Step Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-6478. PoCs published by CodeSecLab. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in MaNGOSWebV4 4.0.6 by injecting a script tag into the 'step' parameter of the installation page. The payload triggers a JavaScript alert, confirming the vulnerability.
Description
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in MaNGOSWebV4 4.0.6 by injecting a script tag into the 'step' parameter of the installation page. The payload triggers a JavaScript alert, confirming the vulnerability.
Nuclei Templates (1)
html:"MaNGOS Web Enhanced V4 Installer"
body="MaNGOS Web Enhanced V4 Installer"
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N