CVE-2008-1479
cyberfrogs cfnetgs 0.24 - Cross-Site Scripting via Directory Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1479. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Cfnetgs 0.24 by injecting a script tag into the 'directory' parameter of the photo/index.php page. The PoC uses a simple alert to display the user's cookies, proving arbitrary script execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in index.php in cyberfrogs.net cfnetgs 0.24 allows remote attackers to inject arbitrary web script or HTML via the directory parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Cfnetgs 0.24 by injecting a script tag into the 'directory' parameter of the photo/index.php page. The PoC uses a simple alert to display the user's cookies, proving arbitrary script execution in the context of the affected site.