CVE-2009-3911
TFTgallery 0.13 - Cross-Site Scripting via Sample Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3911. PoCs published by blake.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in TFTgallery 0.13 by injecting arbitrary JavaScript code via the 'sample' parameter in the settings.php page. The PoC URI shows how an attacker can execute script code in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in settings.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the sample parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in TFTgallery 0.13 by injecting arbitrary JavaScript code via the 'sample' parameter in the settings.php page. The PoC URI shows how an attacker can execute script code in the context of the affected site.