CVE-2009-2216
MEDIUMDirectAdmin < 1.33.6 - Cross-Site Scripting via CMD_REDIRECT URI Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2216. PoCs published by r0t.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in DirectAdmin by injecting arbitrary JavaScript code via the 'sort1' parameter in the URL. The vulnerability arises due to insufficient input sanitization, allowing script execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the URI in a view=advanced request.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in DirectAdmin by injecting arbitrary JavaScript code via the 'sort1' parameter in the URL. The vulnerability arises due to insufficient input sanitization, allowing script execution in the context of the affected site.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N