CVE-2018-19915
MEDIUM NUCLEIDomainMOD 4.09.03-4.11.01 - Stored Cross-Site Scripting via Web Host Name or URL Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-19915. PoCs published by Mohammed Abdul Kareem. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in DomainMOD versions 4.09.03 to 4.11.01. The attacker injects malicious JavaScript into the 'Web Host Name' and 'Web Host's URL' fields, which executes when viewed by other users.
Description
DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in DomainMOD versions 4.09.03 to 4.11.01. The attacker injects malicious JavaScript into the 'Web Host Name' and 'Web Host's URL' fields, which executes when viewed by other users.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N