CVE-2009-1070
ExpressionEngine 1.6.4-1.6.6 - Stored Cross-Site Scripting via Avatar Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1070. PoCs published by Adam Baldwin.
AI-analyzed exploit summary This exploit demonstrates an HTML injection vulnerability in ExpressionEngine versions 1.6.4 through 1.6.6. The PoC shows how attacker-supplied HTML and script code can be executed in the context of the affected browser.
Description
Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter.
Exploits (1)
This exploit demonstrates an HTML injection vulnerability in ExpressionEngine versions 1.6.4 through 1.6.6. The PoC shows how attacker-supplied HTML and script code can be executed in the context of the affected browser.