CVE-2008-2335
Vastal I-Tech phpVID 1.1, 1.2, 1.2.3 - Cross-Site Scripting via Search Results Query Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-2335. PoCs published by 3spi0n, r45c4l.
AI-analyzed exploit summary This document describes multiple vulnerabilities in PhpVID Script, including SQL injection, XSS, and CRLF injection. It provides example URLs to exploit these vulnerabilities but does not include executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in search_results.php in Vastal I-Tech phpVID 1.1 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: some of these details are obtained from third party information. NOTE: it was later reported that 1.2.3 is also affected.
Exploits (2)
This document describes multiple vulnerabilities in PhpVID Script, including SQL injection, XSS, and CRLF injection. It provides example URLs to exploit these vulnerabilities but does not include executable exploit code.
The exploit demonstrates a blind SQL injection vulnerability in the 'cat' parameter of 'groups.php' and a cross-site scripting (XSS) vulnerability in 'search_results.php' for phpVID 1.1. It includes proof-of-concept URLs to trigger these vulnerabilities.