CVE-2009-3057
AOM Software Beex 3 - Cross-Site Scripting via navaction Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-3057. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Beex 3.0 by injecting a script tag into the 'navaction' parameter, which executes arbitrary JavaScript in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in AOM Software Beex 3 allow remote attackers to inject arbitrary web script or HTML via the navaction parameter to (1) news.php and (2) partneralle.php.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Beex 3.0 by injecting a script tag into the 'navaction' parameter, which executes arbitrary JavaScript in the context of the affected site.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Beex 3.0 by injecting a malicious script into the 'Sortieren' parameter of the news.php page. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookie-based authentication credentials.