CVE-2009-4093
Simplog 0.9.3.2 - Cross-Site Scripting via Name or Email Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4093. PoCs published by Amol Naik.
AI-analyzed exploit summary The document describes multiple vulnerabilities in Simplog v0.9.3.2, including persistent XSS, CSRF, and unauthorized comment deletion. It provides technical details and PoC examples for each vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in comments.php in Simplog 0.9.3.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) cname (Name) or (2) email parameters.
Exploits (1)
The document describes multiple vulnerabilities in Simplog v0.9.3.2, including persistent XSS, CSRF, and unauthorized comment deletion. It provides technical details and PoC examples for each vulnerability.