CVE-2018-12095
MEDIUM NUCLEIOEcms v3.1 - Reflected Cross-Site Scripting via info.php mod Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-12095. PoCs published by Renzi. A Nuclei detection template is also available.
AI-analyzed exploit summary This is a reflected XSS vulnerability in OEcms v3.1, where the 'mod' parameter in the 'info.php' endpoint is vulnerable to script injection. The PoC demonstrates a simple payload that triggers a JavaScript prompt when the mouse hovers over the injected element.
Description
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php.
Exploits (1)
This is a reflected XSS vulnerability in OEcms v3.1, where the 'mod' parameter in the 'info.php' endpoint is vulnerable to script injection. The PoC demonstrates a simple payload that triggers a JavaScript prompt when the mouse hovers over the injected element.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N