CVE-2009-2302
Aardvark Topsites PHP <= 5.2.1 - Cross-Site Scripting via Search q Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2302. PoCs published by anonymous.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Aardvark Topsites PHP 5.2.0 by injecting malicious script code via the 'q' parameter in the search functionality. The payload is embedded in a URL, which, when clicked, executes arbitrary JavaScript in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action. NOTE: it was later reported that 5.2.1 is also affected.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Aardvark Topsites PHP 5.2.0 by injecting malicious script code via the 'q' parameter in the search functionality. The payload is embedded in a URL, which, when clicked, executes arbitrary JavaScript in the context of the affected site.