CVE-2009-3225
Almond Classifieds - Cross-Site Scripting via Page or Address Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-3225. PoCs published by Moudi.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in AlmondSoft Almond Classifieds by providing crafted URLs that inject malicious scripts or manipulate SQL queries. The PoC shows how unsanitized user input can lead to cookie theft or arbitrary script execution.
Description
Multiple cross-site scripting (XSS) vulnerabilities in AlmondSoft Almond Classifieds Wap and Pro, and possibly Almond Affiliate Network Classifieds, allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter in a browse action to index.php or (2) the addr parameter to gmap.php. NOTE: some of these details are obtained from third party information.
Exploits (2)
The exploit demonstrates SQL injection and XSS vulnerabilities in AlmondSoft Almond Classifieds by providing crafted URLs that inject malicious scripts or manipulate SQL queries. The PoC shows how unsanitized user input can lead to cookie theft or arbitrary script execution.
The exploit demonstrates an XSS vulnerability in AlmondSoft Almond Classifieds by injecting a script tag into the 'addr' parameter of gmap.php. It also mentions SQL injection vulnerabilities but does not provide a PoC for them.