CVE-2009-4548
ViArt Helpdesk 3.x - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 6 public exploits for CVE-2009-4548. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in ViArt Helpdesk by injecting a malicious script via the 'category_id' parameter. The payload uses obfuscation techniques to bypass basic input filters.
Description
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to forum.php; or the (6) search_category_id parameter to products_search.php.
Exploits (6)
This exploit demonstrates a reflected XSS vulnerability in ViArt Helpdesk by injecting a malicious script via the 'category_id' parameter. The payload uses obfuscation techniques to bypass basic input filters.
This exploit demonstrates a reflected XSS vulnerability in ViArt Helpdesk by injecting a malicious script via the 'category_id' parameter. The payload uses obfuscation techniques (%0D%0A, mixed case) to bypass basic filters.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in ViArt Helpdesk by injecting a malicious script via the 'search_category_id' parameter. The payload uses obfuscation techniques to bypass basic input filters.
This exploit demonstrates a reflected XSS vulnerability in ViArt Helpdesk by injecting a malicious script via the 'category_id' parameter. The PoC uses a crafted URL to execute arbitrary JavaScript in the context of the affected site.
This exploit demonstrates a reflected XSS vulnerability in ViArt Helpdesk by injecting a malicious script via the 'forum_id' parameter. The payload uses obfuscation techniques (%0D%0A, mixed case) to bypass basic filters.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in ViArt Helpdesk by injecting a malicious script via the 'category_id' parameter in the URL. The payload executes arbitrary JavaScript in the context of the affected site.