CVE-2008-4435
RMSOFT Downloads Plus Module 1.5 and 1.7 - Cross-Site Scripting via key or id Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-4435. PoCs published by Lostmon.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in RMSOFT Downloads Plus versions 1.5 and 1.7. It includes a proof-of-concept URL demonstrating how arbitrary script code can be executed due to improper input sanitization.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the RMSOFT Downloads Plus (rmdp) module 1.5 and 1.7 for Xoops allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to search.php and the (2) id parameter to down.php.
Exploits (2)
The provided text describes a cross-site scripting (XSS) vulnerability in RMSOFT Downloads Plus versions 1.5 and 1.7. It includes a proof-of-concept URL demonstrating how arbitrary script code can be executed due to improper input sanitization.
The provided text describes a cross-site scripting (XSS) vulnerability in RMSOFT Downloads Plus versions 1.5 and 1.7. It includes example URLs demonstrating how unsanitized input can be exploited to inject arbitrary script code.