CVE-2009-4469
phpPowerCards 2.0 - Cross-Site Scripting via PATH_INFO, archiv, or subcat Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4469. PoCs published by indoushka.
AI-analyzed exploit summary This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in phpPowerCards 2.0 by injecting malicious JavaScript payloads into the 'archiv' and 'subcat' parameters of the 'pagenumber.inc.php' script. The payloads trigger arbitrary JavaScript execution in the context of the victim's browser.
Description
Multiple cross-site scripting (XSS) vulnerabilities in pagenumber.inc.php in phpPowerCards 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, the (2) archiv parameter, and the (3) subcat parameter.
Exploits (1)
This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in phpPowerCards 2.0 by injecting malicious JavaScript payloads into the 'archiv' and 'subcat' parameters of the 'pagenumber.inc.php' script. The payloads trigger arbitrary JavaScript execution in the context of the victim's browser.