CVE-2008-0207
PRO-Search < 0.17 - Cross-Site Scripting via Multiple URI Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0207. PoCs published by MustLive.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in PRO-Search 0.17 by injecting malicious JavaScript into various URL parameters. The PoC shows how unsanitized input in the 'data' parameter can lead to arbitrary script execution in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prot, (2) host, (3) path, (4) name, (5) ext, (6) size, (7) search_days, or (8) show_page parameter to the default URI.
Exploits (1)
This exploit demonstrates multiple XSS vulnerabilities in PRO-Search 0.17 by injecting malicious JavaScript into various URL parameters. The PoC shows how unsanitized input in the 'data' parameter can lead to arbitrary script execution in the context of the affected site.