Record summary

CVE-2008-5569 has a selected CVSS score of 4.3; EIP currently links 4 catalogued exploits.

Description

Multiple cross-site scripting (XSS) vulnerabilities in PHPepperShop 1.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php or (2) shop/kontakt.php, or (3) shop_kunden_mgmt.php or (4) SHOP_KONFIGURATION.php in shop/Admin/.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
4

Proofs of concept

4

Catalogued exploits

ExploitDBPHPepperShop 1.4 - 'index.php' Cross-Site ScriptingExploitDB exploitby th3.r00k.ieatporkNot analyzed1 file
ExploitDB

PoC details
ExploitDBPHPepperShop 1.4 - 'shop/kontakt.php' Cross-Site ScriptingExploitDB exploitby th3.r00k.ieatporkNot analyzed1 file
ExploitDB

PoC details
ExploitDBPHPepperShop 1.4 - 'shop/Admin/shop_kunden_mgmt.php' Cross-Site ScriptingExploitDB exploitby th3.r00k.ieatporkNot analyzed1 file
ExploitDB

PoC details
ExploitDBPHPepperShop 1.4 - 'shop/Admin/SHOP_KONFIGURATION.php' Cross-Site ScriptingExploitDB exploitby th3.r00k.ieatporkNot analyzed1 file
ExploitDB

PoC details

References

10