Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25405. PoCs published by Ozer Goker.
AI-analyzed exploit summary This exploit demonstrates multiple reflected and stored XSS vulnerabilities in Comodo Dome Firewall 2.7.0. It provides specific URLs, methods, parameters, and payloads for 29 distinct XSS vectors.
Description
Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the newLicense parameter. Attackers can send POST requests to the license activation endpoint with script payloads in the newLicense field to execute arbitrary JavaScript in administrators' browsers.
Exploits (1)
This exploit demonstrates multiple reflected and stored XSS vulnerabilities in Comodo Dome Firewall 2.7.0. It provides specific URLs, methods, parameters, and payloads for 29 distinct XSS vectors.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N