CVE-2008-3771
Pars4u Videosharing 1 - Stored Cross-Site Scripting via PageNo Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3771. PoCs published by Mr.SQL.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in Pars4u Videosharing V1 via the 'cat_id' parameter in 'categories_portal.php'. It brute-forces the admin password by checking character-by-character responses.
Description
Cross-site scripting (XSS) vulnerability in members.php in Pars4u Videosharing 1 allows remote attackers to inject arbitrary web script or HTML via the PageNo parameter.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in Pars4u Videosharing V1 via the 'cat_id' parameter in 'categories_portal.php'. It brute-forces the admin password by checking character-by-character responses.