CVE-2009-3260
LiveStreet 0.2 - Cross-Site Scripting via Topic Header in Comment
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3260. PoCs published by Inj3ct0r.
AI-analyzed exploit summary This exploit demonstrates an XSS vulnerability in LiveStreet 0.2 by injecting an HTML img tag with an onerror event handler that triggers arbitrary JavaScript execution. The vulnerability arises from insufficient input sanitization.
Description
Cross-site scripting (XSS) vulnerability in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the header of the topic in a comment.
Exploits (1)
This exploit demonstrates an XSS vulnerability in LiveStreet 0.2 by injecting an HTML img tag with an onerror event handler that triggers arbitrary JavaScript execution. The vulnerability arises from insufficient input sanitization.