CVE-2008-2962
MyBlog - Cross-Site Scripting via s, sort, or id Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2962. PoCs published by CWH Underground.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in MyBlog CMS. The SQLi PoCs extract admin credentials (unencrypted) via UNION-based attacks, while XSS vectors are identified in multiple parameters.
Description
Multiple cross-site scripting (XSS) vulnerabilities in MyBlog allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) sort parameters to index.php, and the (3) id parameter to post.php.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in MyBlog CMS. The SQLi PoCs extract admin credentials (unencrypted) via UNION-based attacks, while XSS vectors are identified in multiple parameters.