CVE-2008-4083
Brim 2.0 - Authenticated Cross-Site Scripting via Bookmarks Plugin Name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4083. PoCs published by InjEctOr5.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Brim 2.0. The SQLi allows unauthorized retrieval of user credentials, while the XSS can execute arbitrary JavaScript in the context of the victim's browser.
Description
Cross-site scripting (XSS) vulnerability in the Bookmarks plugin in Brim 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in an addItemPost action to index.php. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Brim 2.0. The SQLi allows unauthorized retrieval of user credentials, while the XSS can execute arbitrary JavaScript in the context of the victim's browser.