CVE-2008-2188
EJ3 BlackBook 1.0 - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-2188. PoCs published by Khashayar Fereidani.
AI-analyzed exploit summary This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in BlackBook 1.0 by injecting malicious JavaScript via the 'bookMetaTags' and 'estiloCSS' parameters in the 'header.php' file. The PoC uses simple script tags to trigger an alert with the user's cookies, proving arbitrary script execution in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in EJ3 BlackBook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) bookCopyright and (2) ver parameters to (a) footer.php, and the (3) bookName, (4) bookMetaTags, and (5) estiloCSS parameters to (b) header.php.
Exploits (2)
This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in BlackBook 1.0 by injecting malicious JavaScript via the 'bookMetaTags' and 'estiloCSS' parameters in the 'header.php' file. The PoC uses simple script tags to trigger an alert with the user's cookies, proving arbitrary script execution in the context of the affected site.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in BlackBook 1.0 by injecting arbitrary JavaScript code via the 'bookCopyright' and 'ver' parameters in footer.php. The PoC uses a simple alert to display the user's cookies, proving the vulnerability.