CVE-2008-3202
Xomol CMS 1.2 - Cross-Site Scripting via current_url Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3202. PoCs published by Julian Rodriguez.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in Xomol CMS 1.2 by injecting arbitrary script code via the 'current_url' parameter in the 'tellafriend' operation. The lack of input sanitization allows attackers to execute malicious scripts in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in index.php in Xomol CMS 1.2 allows remote attackers to inject arbitrary web script or HTML via the current_url parameter in a tellafriend action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in Xomol CMS 1.2 by injecting arbitrary script code via the 'current_url' parameter in the 'tellafriend' operation. The lack of input sanitization allows attackers to execute malicious scripts in the context of the affected site.