CVE-2009-4596
PHP Inventory 1.2 - Cross-Site Scripting via sup_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4596. PoCs published by mr_me.
AI-analyzed exploit summary The document describes an authentication bypass and SQL injection vulnerability in PHP Inventory v1.2, including specific payloads for SQLi and reflected XSS. It provides technical details on how to exploit the flaws but does not include functional exploit code.
Description
Cross-site scripting (XSS) vulnerability in index.php in PHP Inventory 1.2 allows remote attackers to inject arbitrary web script or HTML via the sup_id parameter in a suppliers details action.
Exploits (1)
The document describes an authentication bypass and SQL injection vulnerability in PHP Inventory v1.2, including specific payloads for SQLi and reflected XSS. It provides technical details on how to exploit the flaws but does not include functional exploit code.