CVE-2009-2778
GarageSales Script - Cross-Site Scripting via Key Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2778. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in GarageSales Script. It includes live examples of SQLi and blind SQLi via the 'key' parameter, as well as an XSS payload.
Description
Cross-site scripting (XSS) vulnerability in visitor/view.php in GarageSales Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in GarageSales Script. It includes live examples of SQLi and blind SQLi via the 'key' parameter, as well as an XSS payload.