CVE-2009-2114
SkyBlueCanvas 1.1 r237 - Cross-Site Scripting via mgroup mgr objtype id or dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2114. PoCs published by MaXe.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in SkyBlueCanvas by injecting malicious scripts via URL parameters. The PoC includes specific payloads targeting different admin.php endpoints.
Description
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inject arbitrary web script or HTML via the (1) mgroup, (2) mgr, (3) objtype, (4) id, and (5) dir parameters.
Exploits (1)
This exploit demonstrates multiple XSS vulnerabilities in SkyBlueCanvas by injecting malicious scripts via URL parameters. The PoC includes specific payloads targeting different admin.php endpoints.