CVE-2009-3593
Freelancers 1.0 - Cross-Site Scripting via id or jobid Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-3593. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in FreeWebScriptz Freelancer Script 1.0 by injecting a script tag into the 'jobid' parameter of post_resume.php. The PoC triggers an alert dialog, confirming the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Freelancers 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to placebid.php and (2) jobid parameter to post_resume.php.
Exploits (2)
This exploit demonstrates a reflected XSS vulnerability in FreeWebScriptz Freelancer Script 1.0 by injecting a script tag into the 'jobid' parameter of post_resume.php. The PoC triggers an alert dialog, confirming the vulnerability.
This exploit demonstrates a reflected XSS vulnerability in FreeWebScriptz Freelancer Script 1.0 by injecting a script tag into the 'id' parameter of the 'placebid.php' endpoint. The PoC triggers an arbitrary JavaScript alert, confirming the vulnerability.