CVE-2009-1951
PropertyMax Pro FREE 0.3 - Cross-Site Scripting via pl Parameter in mi Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1951. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates SQL injection for authentication bypass and XSS in PropertyMax Pro FREE. The SQLi bypasses login by manipulating the query, while the XSS executes arbitrary JavaScript via a crafted URL parameter.
Description
Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbitrary web script or HTML via the pl parameter in a mi action.
Exploits (1)
This exploit demonstrates SQL injection for authentication bypass and XSS in PropertyMax Pro FREE. The SQLi bypasses login by manipulating the query, while the XSS executes arbitrary JavaScript via a crafted URL parameter.