CVE-2009-4359
SmartMedia 0.85 Beta - Cross-Site Scripting via CategoryID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4359. PoCs published by SoldierOfAllah.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in the SmartMedia module for XOOPS by injecting arbitrary JavaScript code via the 'categoryid' parameter. The vulnerability arises due to insufficient sanitization of user-supplied input.
Description
Cross-site scripting (XSS) vulnerability in folder.php in the SmartMedia 0.85 Beta module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the categoryid parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in the SmartMedia module for XOOPS by injecting arbitrary JavaScript code via the 'categoryid' parameter. The vulnerability arises due to insufficient sanitization of user-supplied input.