CVE-2018-1000638
MEDIUMMiniCMS 1.1 - Cross-Site Scripting via Date Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-1000638. PoCs published by CodeSecLab.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in MiniCMS 1.10 via the 'date' GET parameter, which is directly echoed without proper sanitization. The payload injects a script tag into the HTML context, triggering an alert.
Description
MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in MiniCMS 1.10 via the 'date' GET parameter, which is directly echoed without proper sanitization. The payload injects a script tag into the HTML context, triggering an alert.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N