CVE-2009-3191
PAD Site Scripts 3.6 - Cross-Site Scripting via cat Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3191. PoCs published by Mr.SQL.
AI-analyzed exploit summary The exploit demonstrates a remote SQL injection vulnerability in PAD Site Scripts v3.6 via the 'list.php' parameter 'string'. It also includes an XSS vulnerability in 'rss.php' and 'opml.php' via the 'cat' parameter. The SQLi payload extracts table and column names from the INFORMATION_SCHEMA.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to inject arbitrary web script or HTML via the cat parameter to (1) rss.php and (2) opml.php.
Exploits (1)
The exploit demonstrates a remote SQL injection vulnerability in PAD Site Scripts v3.6 via the 'list.php' parameter 'string'. It also includes an XSS vulnerability in 'rss.php' and 'opml.php' via the 'cat' parameter. The SQLi payload extracts table and column names from the INFORMATION_SCHEMA.