CVE-2008-3560
Kshop module 2.22 for Xoops - Cross-Site Scripting via Search Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3560. PoCs published by Lostmon.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Kshop 2.22 by providing a form that submits unsanitized input to the search parameter. The vulnerability allows arbitrary script execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in kshop_search.php in the Kshop module 2.22 for Xoops allows remote attackers to inject arbitrary web script or HTML via the search parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Kshop 2.22 by providing a form that submits unsanitized input to the search parameter. The vulnerability allows arbitrary script execution in the context of the affected site.