CVE-2008-2842
doitlive/cms < 2.50 - Cross-Site Scripting via FILE Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2842. PoCs published by BugReport.IR.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in doITlive CMS <=2.50. It includes PoC URLs for SQLi in the 'ID' parameter and cookie-based auth bypass, as well as an XSS payload in the 'File' parameter.
Description
Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in doITLive CMS 2.50 and earlier allows remote attackers to inject arbitrary web script or HTML via the FILE parameter.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in doITlive CMS <=2.50. It includes PoC URLs for SQLi in the 'ID' parameter and cookie-based auth bypass, as well as an XSS payload in the 'File' parameter.