CVE-2008-2694
phpinv 0.8.0 - Cross-Site Scripting via Search Keyword Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2694. PoCs published by CWH Underground.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in PHPInv 0.8.0 via the 'action' parameter in entry.php, allowing arbitrary file inclusion. It also includes an XSS vulnerability in search.php via the 'keyword' parameter.
Description
Cross-site scripting (XSS) vulnerability in search.php in phpInv 0.8.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in PHPInv 0.8.0 via the 'action' parameter in entry.php, allowing arbitrary file inclusion. It also includes an XSS vulnerability in search.php via the 'keyword' parameter.