CVE-2008-2994
PHPEasyData 1.5.4 - Cross-Site Scripting via Annuaire Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-2994. PoCs published by Sylvain THUAL.
AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in PHPEasyData 1.5.4 due to improper input sanitization. It includes a sample XSS payload but lacks executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to inject arbitrary web script or HTML via the (1) annuaire parameter to (a) last_records.php and (b) annuaire.php and the (2) by and (3) cat_id parameters to annuaire.php.
Exploits (2)
The provided text describes SQL injection and XSS vulnerabilities in PHPEasyData 1.5.4 due to improper input sanitization. It includes a sample XSS payload but lacks executable exploit code.
The provided text describes multiple SQL injection and XSS vulnerabilities in PHPEasyData 1.5.4 due to improper input sanitization. It includes example URLs demonstrating XSS payloads but does not contain executable exploit code.