CVE-2008-3098
fuzzylime_cms < 3.03 - Cross-Site Scripting via Login Form User Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3098. PoCs published by Fabian Fingerle.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in fuzzylime CMS versions prior to 3.03. The PoC uses a crafted form submission to inject malicious JavaScript into the 'user' parameter, which is then executed in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in admin/usercheck.php in fuzzylime (cms) before 3.03 allows remote attackers to inject arbitrary web script or HTML via the user parameter to the login form.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in fuzzylime CMS versions prior to 3.03. The PoC uses a crafted form submission to inject malicious JavaScript into the 'user' parameter, which is then executed in the context of the affected site.