CVE-2009-1321
ASP Product Catalog 1.0 - Cross-Site Scripting via Search Keywords Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1321. PoCs published by AlpHaNiX.
AI-analyzed exploit summary This Perl script exploits two vulnerabilities in ASP Product Catalog: an XSS vulnerability in the search functionality and a database disclosure vulnerability allowing direct access to the MDB file. It uses LWP::UserAgent to send crafted requests and verify exploitation.
Description
Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
Exploits (1)
This Perl script exploits two vulnerabilities in ASP Product Catalog: an XSS vulnerability in the search functionality and a database disclosure vulnerability allowing direct access to the MDB file. It uses LWP::UserAgent to send crafted requests and verify exploitation.