CVE-2009-4685
PHP Scripts Now Astrology - Cross-Site Scripting via Day Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4685. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in the Astrology application by injecting arbitrary JavaScript code via the 'day' parameter in the URL. The payload uses obfuscation techniques (e.g., mixed case, URL encoding) to bypass basic input sanitization.
Description
Cross-site scripting (XSS) vulnerability in celebrities.php in PHP Scripts Now Astrology allows remote attackers to inject arbitrary web script or HTML via the day parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in the Astrology application by injecting arbitrary JavaScript code via the 'day' parameter in the URL. The payload uses obfuscation techniques (e.g., mixed case, URL encoding) to bypass basic input sanitization.