Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-4157. PoCs published by MustLive.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in the Joomla! ProofReader component by injecting arbitrary JavaScript code via maliciously crafted URIs. The PoC shows how an attacker can steal cookie-based authentication credentials by enticing a user to click on a malicious link.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in (1) 404 or (2) error pages.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in the Joomla! ProofReader component by injecting arbitrary JavaScript code via maliciously crafted URIs. The PoC shows how an attacker can steal cookie-based authentication credentials by enticing a user to click on a malicious link.