CVE-2009-1614
Leap CMS 0.1.4 - Cross-Site Scripting via Message or Search Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1614. PoCs published by YEnH4ckEr.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Leap CMS 0.1.4, including SQL injection for authentication bypass, XSS for cookie stealing, and shell upload. The PoC provides clear steps and payloads for each vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the msg parameter (aka the message in an article comment) or (2) the searchterm parameter (aka the search post form). NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in Leap CMS 0.1.4, including SQL injection for authentication bypass, XSS for cookie stealing, and shell upload. The PoC provides clear steps and payloads for each vulnerability.