CVE-2009-4522
BloofoxCMS 0.3.5 - Cross-Site Scripting via Search Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4522. PoCs published by drunken danish rednecks.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in bloofoxCMS 0.3.5, where the 'search' parameter fails to sanitize user input, allowing arbitrary script execution. The example URL demonstrates a basic XSS payload.
Description
Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter to index.php. NOTE: some of these details are obtained from third party information.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in bloofoxCMS 0.3.5, where the 'search' parameter fails to sanitize user input, allowing arbitrary script execution. The example URL demonstrates a basic XSS payload.