CVE-2009-3714
MCshoutbox 1.1 - Cross-Site Scripting via admin_login.php loginerror Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3714. PoCs published by SirGod.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in MCshoutbox 1.1, including SQL injection for authentication bypass, XSS via the 'loginerror' parameter, and unrestricted file upload leading to remote shell execution. The PoC includes specific payloads and vulnerable code snippets.
Description
Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in MCshoutbox 1.1, including SQL injection for authentication bypass, XSS via the 'loginerror' parameter, and unrestricted file upload leading to remote shell execution. The PoC includes specific payloads and vulnerable code snippets.