CVE-2008-0547
CandyPress < 4.1.1.26 - Cross-Site Scripting via helpfield Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0547. PoCs published by BugReport.IR.
AI-analyzed exploit summary The exploit demonstrates SQL injection, XSS, and path disclosure vulnerabilities in CandyPress eCommerce suite version 4.1.1.26. It includes functional PoC URLs to extract sensitive data such as admin credentials, payment details, and configuration settings.
Description
Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, allows remote attackers to inject arbitrary web script or HTML via the helpfield parameter.
Exploits (1)
The exploit demonstrates SQL injection, XSS, and path disclosure vulnerabilities in CandyPress eCommerce suite version 4.1.1.26. It includes functional PoC URLs to extract sensitive data such as admin credentials, payment details, and configuration settings.