CVE-2009-3601
Scriptsez Ultimate Poll - Cross-Site Scripting via demo_page.php clr Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3601. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Ultimate Poll by injecting arbitrary JavaScript code via the 'clr' parameter in the URL. The payload bypasses basic sanitization by using HTML encoding and line breaks.
Description
Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script or HTML via the clr parameter in a vote action.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Ultimate Poll by injecting arbitrary JavaScript code via the 'clr' parameter in the URL. The payload bypasses basic sanitization by using HTML encoding and line breaks.