CVE-2008-2117
Project Alumni 1.0.9 - Cross-Site Scripting via News Page Year Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2117. PoCs published by hadihadi.
AI-analyzed exploit summary The code describes a cross-site scripting (XSS) and SQL injection vulnerability in Project Alumni 1.0.9. It provides a proof-of-concept URL demonstrating the XSS vulnerability but lacks executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in pages/news.page.inc in Project Alumni 1.0.9 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a news action to index.php, a different vector than CVE-2007-6126.
Exploits (1)
The code describes a cross-site scripting (XSS) and SQL injection vulnerability in Project Alumni 1.0.9. It provides a proof-of-concept URL demonstrating the XSS vulnerability but lacks executable exploit code.