CVE-2009-0526
AdaptCMS Lite 1.4 - Cross-Site Scripting via URL and acuparam Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0526. PoCs published by RoMaNcYxHaCkEr.
AI-analyzed exploit summary The exploit demonstrates Remote File Include (RFI) and Cross-Site Scripting (XSS) vulnerabilities in AdaptCMS Lite 1.4. The RFI allows remote code execution by including a malicious file via the 'sitepath' parameter, while the XSS vulnerabilities exploit unsanitized input in the 'view' and 'acuparam' parameters.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdaptCMS Lite 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) url and (2) acuparam parameters, and (3) the URI.
Exploits (1)
The exploit demonstrates Remote File Include (RFI) and Cross-Site Scripting (XSS) vulnerabilities in AdaptCMS Lite 1.4. The RFI allows remote code execution by including a malicious file via the 'sitepath' parameter, while the XSS vulnerabilities exploit unsanitized input in the 'view' and 'acuparam' parameters.