CVE-2005-1498
myBloggie 2.1.1 - Cross-Site Scripting via Year Parameter in viewmode.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-1498. PoCs published by Alberto Trivero.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in myBloggie, including XSS and HTML injection via URL parameters. It provides specific payloads to trigger these vulnerabilities.
Description
Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) year parameter in viewmode.php, or the (2) cat_id, (3) month_no, or (4) post_id parameter in index.php, which are not properly sanitized before they are displayed in an error message. NOTE: issues 2, 3, and 4 may be due to a problem in associated products rather than myBloggie itself.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in myBloggie, including XSS and HTML injection via URL parameters. It provides specific payloads to trigger these vulnerabilities.