CVE-2009-4822
Kasseler CMS 1.3.4 - Cross-Site Scripting via do id or uname Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-4822. PoCs published by Gamoscu, indoushka.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in Kasseler CMS by injecting JavaScript code via unsanitized URL parameters. It targets specific modules and parameters to trigger the vulnerabilities.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) do, (2) id, and (3) uname parameters.
Exploits (2)
The exploit demonstrates multiple XSS vulnerabilities in Kasseler CMS by injecting JavaScript code via unsanitized URL parameters. It targets specific modules and parameters to trigger the vulnerabilities.
This exploit describes an information disclosure vulnerability in Kasseler CMS 2.0.5 where backup files containing sensitive user data (including admin credentials) are exposed. Additionally, an XSS vulnerability is mentioned but not detailed.