CVE-2018-10078
MEDIUMGeist WatchDog Console 3.2.2 - Authenticated Stored Cross-Site Scripting via Server Description
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-10078. PoCs published by bzyo.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Geist WatchDog Console 3.2.2, including XXE, XSS, and insecure file permissions. It provides detailed steps to exploit each vulnerability, including file manipulation and remote data exfiltration.
Description
Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a server description.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in Geist WatchDog Console 3.2.2, including XXE, XSS, and insecure file permissions. It provides detailed steps to exploit each vulnerability, including file manipulation and remote data exfiltration.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N