CVE-2008-4432
RMSOFT MiniShop module 1.0 - Cross-Site Scripting via search.php itemsxpag Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4432. PoCs published by Lostmon.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in RMSOFT MiniShop by injecting arbitrary JavaScript via unsanitized input parameters in the search.php module. The PoC includes three separate payloads targeting different parameters.
Description
Cross-site scripting (XSS) vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops allows remote attackers to inject arbitrary web script or HTML via the itemsxpag parameter.
Exploits (1)
This exploit demonstrates multiple XSS vulnerabilities in RMSOFT MiniShop by injecting arbitrary JavaScript via unsanitized input parameters in the search.php module. The PoC includes three separate payloads targeting different parameters.