CVE-2008-5933
CMS ISWEB 3.0 - Cross-Site Scripting via strcerca or id_oggetto Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5933. PoCs published by XaDoS.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in IsWeb CMS v3.0. It includes specific payloads for blind SQL injection and XSS attacks, with examples targeting vulnerable parameters.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in CMS ISWEB 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the strcerca parameter (aka the input field for the cerca action) or (2) the id_oggetto parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in IsWeb CMS v3.0. It includes specific payloads for blind SQL injection and XSS attacks, with examples targeting vulnerable parameters.