CVE-2009-3493
Zenas PaoBacheca Guestbook 2.1 - Cross-Site Scripting via PATH_INFO
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-3493. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in PaoBacheca 2.1 by injecting a script tag into the URL, which executes arbitrary JavaScript in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) scrivi.php and (2) index.php.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in PaoBacheca 2.1 by injecting a script tag into the URL, which executes arbitrary JavaScript in the context of the affected site.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in PaoBacheca 2.1 by injecting a script tag into the URL path. The PoC triggers an alert with the user's cookies, confirming the vulnerability.