Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-3679. PoCs published by Stink', sl4xUz.
AI-analyzed exploit summary This is a writeup describing XSS and upload vulnerabilities in PhpLinkExchange v1.02. It provides URLs for exploitation but does not include functional exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in IDevSpot PhpLinkExchange 1.01 allow remote attackers to inject arbitrary web script or HTML via the catid parameter in a (1) user_add, (2) recip, (3) tellafriend, or (4) contact action, or (5) in a request without an action; or (6) the id parameter in a tellafriend action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (2)
This is a writeup describing XSS and upload vulnerabilities in PhpLinkExchange v1.02. It provides URLs for exploitation but does not include functional exploit code.
The provided text describes multiple XSS vulnerabilities in PhPLinkExchange 1.01 due to insufficient input sanitization. It includes example URLs demonstrating how an attacker could inject malicious scripts via the 'catid' and 'id' parameters.