CVE-2007-3291
LiveCMS <= 3.4 - Cross-Site Scripting via Article Name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3291. PoCs published by g00ns.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in LiveCMS <= 3.4 via the 'cid' parameter in categoria.php. It retrieves admin credentials (username and password hash) and attempts to crack the hash using an external service.
Description
Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name, possibly involving the titulo parameter in article.php.
Exploits (1)
This Perl script exploits a SQL injection vulnerability in LiveCMS <= 3.4 via the 'cid' parameter in categoria.php. It retrieves admin credentials (username and password hash) and attempts to crack the hash using an external service.