CVE-2022-36664
MEDIUMPassword Manager for IIS 2.0 - Cross-Site Scripting via ResultURL Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-36664. PoCs published by VP4TR10T.
AI-analyzed exploit summary This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in Password Manager for IIS v2.0. The payload is injected via the 'ReturnURL' parameter in a POST request to '/isapi/PasswordManager.dll', executing arbitrary JavaScript code.
Description
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter.
Exploits (1)
This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in Password Manager for IIS v2.0. The payload is injected via the 'ReturnURL' parameter in a POST request to '/isapi/PasswordManager.dll', executing arbitrary JavaScript code.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N