Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3380. PoCs published by Dr.Crash.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in EasyBookMarker 4.0tr by injecting malicious JavaScript into a form submission. The PoC uses a hidden form with an onLoad event to automatically submit the payload, triggering an alert with the user's cookies.
Description
Cross-site scripting (XSS) vulnerability in ajaxp_backend.php in MyioSoft EasyBookMarker 4.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the rs parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in EasyBookMarker 4.0tr by injecting malicious JavaScript into a form submission. The PoC uses a hidden form with an onLoad event to automatically submit the payload, triggering an alert with the user's cookies.