CVE-2009-1607
LinkBase 2.0 - Stored Cross-Site Scripting via Username Registration
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1607. PoCs published by SirGod.
AI-analyzed exploit summary This exploit leverages a stored XSS vulnerability in LinkBase 2.0 to steal admin cookies by injecting a malicious script into the registration process. The stolen cookies are logged to a remote server controlled by the attacker.
Description
Cross-site scripting (XSS) vulnerability in the administrator panel in phpForm.net LinkBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the username in a registration, which is not properly handled when the administrator accesses the Users menu.
Exploits (1)
This exploit leverages a stored XSS vulnerability in LinkBase 2.0 to steal admin cookies by injecting a malicious script into the registration process. The stolen cookies are logged to a remote server controlled by the attacker.