CVE-2009-2228
Kasseler CMS - Cross-Site Scripting via URL Parameter in Redirect Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2228. PoCs published by S(r1pt.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Kasseler CMS via the 'file' parameter in engine.php, allowing unauthorized file disclosure. It also includes an XSS vulnerability via the 'url' parameter in the redirect function.
Description
Cross-site scripting (XSS) vulnerability in engine.php in Kasseler CMS allows remote attackers to inject arbitrary web script or HTML via the url parameter in a redirect action.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in Kasseler CMS via the 'file' parameter in engine.php, allowing unauthorized file disclosure. It also includes an XSS vulnerability via the 'url' parameter in the redirect function.