CVE-2009-3348
Datavore Gyro 5.0 - Cross-Site Scripting via Home Component cid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3348. PoCs published by OoN_Boy.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Gyro V5.0 by manipulating the 'cid' parameter in the 'op=cat' endpoint. It includes proof-of-concept URLs showing how to extract database version information and execute arbitrary JavaScript.
Description
Cross-site scripting (XSS) vulnerability in Datavore Gyro 5.0 allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a cat action to the home component.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Gyro V5.0 by manipulating the 'cid' parameter in the 'op=cat' endpoint. It includes proof-of-concept URLs showing how to extract database version information and execute arbitrary JavaScript.