CVE-2008-2445
Web Group Communication Center 1.0.3 PreRelease 1 and earlier - Cross-Site Scripting via UserID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2445. PoCs published by myvx.
AI-analyzed exploit summary This exploit demonstrates XSS and SQL injection vulnerabilities in Web Group Communication Center. The XSS payload bypasses filters via URL encoding, while the SQLi extracts user credentials from the database.
Description
Cross-site scripting (XSS) vulnerability in profile.php in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the userid parameter in a show action.
Exploits (1)
This exploit demonstrates XSS and SQL injection vulnerabilities in Web Group Communication Center. The XSS payload bypasses filters via URL encoding, while the SQLi extracts user credentials from the database.