CVE-2009-4651
Webee Comments 1.1.1, 1.2, 2.0 - Cross-Site Scripting via BBCode Tags
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4651. PoCs published by Jeff Channell.
AI-analyzed exploit summary The provided text describes SQL-injection and HTML-injection vulnerabilities in the Joomla! Webee component, including example payloads for XSS attacks. It does not contain executable exploit code but outlines the vulnerabilities and potential attack vectors.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) color, (2) img, or (3) url BBCode tags in unspecified vectors.
Exploits (1)
The provided text describes SQL-injection and HTML-injection vulnerabilities in the Joomla! Webee component, including example payloads for XSS attacks. It does not contain executable exploit code but outlines the vulnerabilities and potential attack vectors.