CVE-2008-6385
W3matter RevSense 1.0 - Cross-Site Scripting via Section Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6385. PoCs published by Pouya_Server.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in RevSense 1.0 by providing crafted URLs that inject malicious input into the 'section', 'action', and form fields. These can be used to manipulate database queries or execute arbitrary JavaScript in the context of a user's session.
Description
Cross-site scripting (XSS) vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in RevSense 1.0 by providing crafted URLs that inject malicious input into the 'section', 'action', and form fields. These can be used to manipulate database queries or execute arbitrary JavaScript in the context of a user's session.