CVE-2009-2571
VerliAdmin 0.3.7-0.3.8 - Cross-Site Scripting via URI or Query Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2571. PoCs published by TEAMELITE.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in VerliAdmin by injecting arbitrary JavaScript code via unsanitized input parameters. The PoC includes crafted URLs that trigger script execution in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in VerliAdmin 0.3.7 and 0.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the URI, (2) the q parameter, (3) the nick parameter, or (4) the nick parameter in a bantest action.
Exploits (1)
This exploit demonstrates multiple XSS vulnerabilities in VerliAdmin by injecting arbitrary JavaScript code via unsanitized input parameters. The PoC includes crafted URLs that trigger script execution in the context of the affected site.