CVE-2019-25422
HIGHComodo Dome Firewall < 2.7.0 - Cross-Site Scripting via VPNFW Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25422. PoCs published by Ozer Goker.
AI-analyzed exploit summary The exploit demonstrates multiple reflected and stored XSS vulnerabilities in Comodo Dome Firewall 2.7.0 by providing specific URLs, methods, parameters, and payloads. It includes 29 distinct XSS vectors, each with clear instructions for exploitation.
Description
Comodo Dome Firewall 2.7.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the vpnfw endpoint. Attackers can submit POST requests with script payloads in the target parameter for reflected XSS or the remark parameter for stored XSS to execute arbitrary JavaScript in administrator browsers.
Exploits (1)
The exploit demonstrates multiple reflected and stored XSS vulnerabilities in Comodo Dome Firewall 2.7.0 by providing specific URLs, methods, parameters, and payloads. It includes 29 distinct XSS vectors, each with clear instructions for exploitation.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N