CVE-2009-4168
WP-Cumulus < 1.23 - Cross-Site Scripting via Tagcloud Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4168. PoCs published by MustLive.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in WP-Cumulus plugin for WordPress by injecting malicious JavaScript code via the 'tagcloud' parameter in the SWF file. The vulnerability allows arbitrary script execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action. Cross-site scripting (XSS) vulnerability in tagcloud.swf in the WP-Cumulus Plug-in before 1.23 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in WP-Cumulus plugin for WordPress by injecting malicious JavaScript code via the 'tagcloud' parameter in the SWF file. The vulnerability allows arbitrary script execution in the context of the affected site.