CVE-2009-3601

Scriptsez Ultimate Poll - Cross-Site Scripting via demo_page.php clr Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-3601. PoCs published by Moudi.

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Ultimate Poll by injecting arbitrary JavaScript code via the 'clr' parameter in the URL. The payload bypasses basic sanitization by using HTML encoding and line breaks.

Description

Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script or HTML via the clr parameter in a vote action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34783

This exploit demonstrates a cross-site scripting (XSS) vulnerability in Ultimate Poll by injecting arbitrary JavaScript code via the 'clr' parameter in the URL. The payload bypasses basic sanitization by using HTML encoding and line breaks.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Ultimate Poll (version not specified)
No auth needed
Prerequisites: Access to a vulnerable Ultimate Poll instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/55914
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/51773
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35834

Scores

EPSS 0.0303
EPSS Percentile 85.7%

Details

CWE
CWE-79
Status published
Products (1)
scriptsez/ultimate_poll
Published Oct 08, 2009
Tracked Since Feb 18, 2026