CVE-2009-4729
x10media adult_script 1.7 - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4729. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in x10 Media Adult Script 1.7. It includes live examples of SQLi and XSS payloads targeting specific parameters in the application.
Description
Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, (3) id parameter to templates/header1.php, and (4) key parameter to video_listing.php.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in x10 Media Adult Script 1.7. It includes live examples of SQLi and XSS payloads targeting specific parameters in the application.