CVE-2019-15501
MEDIUM NUCLEILISTSERV < 16.5-2018a - Reflected Cross-Site Scripting via OK Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-15501. PoCs published by MTK. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in LSoft ListServ versions prior to 16.5-2018a. The payload is injected via the 'OK' parameter in the URL, triggering JavaScript execution in the context of the victim's browser.
Description
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in LSoft ListServ versions prior to 16.5-2018a. The payload is injected via the 'OK' parameter in the URL, triggering JavaScript execution in the context of the victim's browser.
Nuclei Templates (1)
http.html:"LISTSERV" || http.html:"listserv"
body="listserv"
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N