Exploitation Summary
EIP tracks 2 public exploits for CVE-2009-4544. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Facil Helpdesk, including XSS, LFI, and RFI. The PoC provides specific URLs to exploit these vulnerabilities, particularly targeting the 'lng' parameter in index.php and the path in kbase.php.
Description
Cross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
Exploits (2)
This exploit demonstrates multiple vulnerabilities in Facil Helpdesk, including XSS, LFI, and RFI. The PoC provides specific URLs to exploit these vulnerabilities, particularly targeting the 'lng' parameter in index.php and the path in kbase.php.
The provided text describes multiple input-validation vulnerabilities in Facil Helpdesk, including XSS and file inclusion flaws, but does not contain functional exploit code. It references a proof-of-concept URL for XSS.