CVE-2009-2772
PG Roommate Finder Solution - Cross-Site Scripting via Part Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-2772. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in PG Roommate Finder Solution by injecting a script tag into the 'part' parameter of viewprofile.php, which executes arbitrary JavaScript in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbitrary web script or HTML via the part parameter to (1) quick_search.php and (2) viewprofile.php.
Exploits (2)
This exploit demonstrates a reflected XSS vulnerability in PG Roommate Finder Solution by injecting a script tag into the 'part' parameter of viewprofile.php, which executes arbitrary JavaScript in the context of the affected site.
This exploit demonstrates a reflected XSS vulnerability in PG Roommate Finder Solution by injecting a script tag into the 'part' parameter of quick_search.php, which executes arbitrary JavaScript in the context of the affected site.