CVE-2009-3066
Property Watch 2.0 - Cross-Site Scripting via VideoID or Redirect Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-3066. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Property Watch 2.0 by injecting a malicious script via the 'redirect' parameter in the login.php URL. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies or performing other malicious actions.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PropertyWatchScript.com Property Watch 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) videoid parameter to tools/email.php and (2) redirect parameter to tools/login.php.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Property Watch 2.0 by injecting a malicious script via the 'redirect' parameter in the login.php URL. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies or performing other malicious actions.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Property Watch 2.0 by injecting a malicious script via the 'videoid' parameter in the email.php endpoint. The script executes arbitrary JavaScript to steal cookie-based authentication credentials.