CVE-2009-2928
TGS Content Management 0.x - Cross-Site Scripting via login.php previous_page Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2928. PoCs published by []ViZiOn.
AI-analyzed exploit summary This is a detailed technical writeup describing multiple vulnerabilities in TGS CMS, including XSS, SQL injection, blind SQL/XPath injection, and source code disclosure. It provides affected endpoints, examples, and mitigation strategies but does not include functional exploit code.
Description
Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject arbitrary web script or HTML via the previous_page parameter, a different vector than CVE-2008-6839.
Exploits (1)
This is a detailed technical writeup describing multiple vulnerabilities in TGS CMS, including XSS, SQL injection, blind SQL/XPath injection, and source code disclosure. It provides affected endpoints, examples, and mitigation strategies but does not include functional exploit code.