CVE-2009-0699
Plunet BusinessManager < 4.1 - Authenticated Cross-Site Scripting via QUB or Bez74 Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0699. PoCs published by Matteo Ignaccolo.
AI-analyzed exploit summary This exploit demonstrates an HTML injection vulnerability in Plunet BusinessManager by injecting malicious script tags into form fields. The vulnerability allows arbitrary script execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the (1) QUB and (2) Bez74 parameters.
Exploits (1)
This exploit demonstrates an HTML injection vulnerability in Plunet BusinessManager by injecting malicious script tags into form fields. The vulnerability allows arbitrary script execution in the context of the affected site.