CVE-2008-7057
BandSite CMS 1.1.4 - Cross-Site Scripting via Merchandise Type Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7057. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in BandSite CMS 1.1.4, including arbitrary database download, XSS, and CSRF. The PoC provides direct URLs to trigger these issues without requiring authentication for some vectors.
Description
Cross-site scripting (XSS) vulnerability in merchandise.php in BandSite CMS 1.1.4 allows remote attackers to inject arbitrary HTML or web script via the type parameter.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in BandSite CMS 1.1.4, including arbitrary database download, XSS, and CSRF. The PoC provides direct URLs to trigger these issues without requiring authentication for some vectors.