CVE-2009-2783
XOOPS 2.3.3 - Cross-Site Scripting via op Parameter and Query String
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2783. PoCs published by Sense of Security.
AI-analyzed exploit summary The exploit demonstrates XSS vulnerabilities in XOOPS 2.3.3 by injecting arbitrary JavaScript via unsanitized user input in the 'op' and 'user.php' parameters. The PoC uses simple script tags to trigger an alert, confirming the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parameter to modules/pm/viewpmsg.php and (2) query string to modules/profile/user.php.
Exploits (1)
The exploit demonstrates XSS vulnerabilities in XOOPS 2.3.3 by injecting arbitrary JavaScript via unsanitized user input in the 'op' and 'user.php' parameters. The PoC uses simple script tags to trigger an alert, confirming the vulnerability.