CVE-2009-4746
Dreamlevels DreamPoll 3.1 - Cross-Site Scripting via recordsPerPage Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4746. PoCs published by Mark from infosecstuff.
AI-analyzed exploit summary The document describes XSS and SQL injection vulnerabilities in DreamPoll 3.1, including examples of exploit payloads for blind SQL injection and timing attacks. It provides technical details but lacks executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in index.php in Dreamlevels DreamPoll 3.1 allows remote attackers to inject arbitrary web script or HTML via the recordsPerPage parameter in a poll_default login action.
Exploits (1)
The document describes XSS and SQL injection vulnerabilities in DreamPoll 3.1, including examples of exploit payloads for blind SQL injection and timing attacks. It provides technical details but lacks executable exploit code.