CVE-2008-2911
Contenido 4.8.4 - Cross-Site Scripting via Contenido, Belang, or Username Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2911. PoCs published by RoMaNcYxHaCkEr.
AI-analyzed exploit summary This exploit demonstrates multiple RFI (Remote File Inclusion) and XSS (Cross-Site Scripting) vulnerabilities in Contenido CMS version 4.8.4. The RFI vulnerabilities allow remote code execution by including malicious files via manipulated parameters, while the XSS vulnerability enables arbitrary JavaScript execution.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, and (3) username parameters.
Exploits (1)
This exploit demonstrates multiple RFI (Remote File Inclusion) and XSS (Cross-Site Scripting) vulnerabilities in Contenido CMS version 4.8.4. The RFI vulnerabilities allow remote code execution by including malicious files via manipulated parameters, while the XSS vulnerability enables arbitrary JavaScript execution.