CVE-2005-4285
Dick Copits PDEstore < 1.8 - Cross-Site Scripting via Search Module, Product, or Cart ID Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4285. PoCs published by r0t3d3Vil.
AI-analyzed exploit summary This exploit demonstrates cross-site scripting (XSS) vulnerabilities in PDEstore by injecting arbitrary JavaScript code via unsanitized input parameters. The PoC provides example URLs that trigger XSS payloads when processed by the vulnerable application.
Description
Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters.
Exploits (1)
This exploit demonstrates cross-site scripting (XSS) vulnerabilities in PDEstore by injecting arbitrary JavaScript code via unsanitized input parameters. The PoC provides example URLs that trigger XSS payloads when processed by the vulnerable application.