CVE-2022-39195
MEDIUM NUCLEILISTSERV 17 - Cross-Site Scripting via c Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-39195. PoCs published by Shaunt Der-Grigorian. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in LISTSERV 17 via the 'c' parameter. The PoC shows how arbitrary JavaScript can be injected and executed in the context of the victim's browser.
Description
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in LISTSERV 17 via the 'c' parameter. The PoC shows how arbitrary JavaScript can be injected and executed in the context of the victim's browser.
Nuclei Templates (1)
http.html:"LISTSERV" || http.html:"listserv"
body="listserv"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N