Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0764.
AI-analyzed exploit summary The exploit demonstrates three vulnerabilities in Kipper 2.01: remote data reading via direct file access, local file inclusion via path traversal, and remote XSS via crafted input. The PoC provides direct URLs to exploit these issues.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Kipper 2.01 allow remote attackers to inject arbitrary web script or HTML via the charm parameter to (1) index.php and (2) kipper.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The exploit demonstrates three vulnerabilities in Kipper 2.01: remote data reading via direct file access, local file inclusion via path traversal, and remote XSS via crafted input. The PoC provides direct URLs to exploit these issues.