CVE-2008-1991
Acidcat CMS 3.4.1 - Cross-Site Scripting via admin_colors_swatch.asp field Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1991. PoCs published by BugReport.IR.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Acidcat CMS 3.4.1, including SQL injection for credential theft, authentication bypass, XSS, and unauthorized file upload via FCKEditor. It provides functional PoC code for these issues.
Description
Cross-site scripting (XSS) vulnerability in admin_colors_swatch.asp in Acidcat CMS 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the field parameter.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Acidcat CMS 3.4.1, including SQL injection for credential theft, authentication bypass, XSS, and unauthorized file upload via FCKEditor. It provides functional PoC code for these issues.