CVE-2009-4864
I-Escorts Directory Script and Agency Script - Cross-Site Scripting via search_name or languages Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4864. PoCs published by 599eme Man.
AI-analyzed exploit summary This is a vulnerability writeup describing multiple XSS vulnerabilities in I-Escorts products due to improper input sanitization. It provides an example URL but does not include functional exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script allow remote attackers to inject arbitrary web script or HTML via the (1) search_name and (2) languages parameters. NOTE: some of these details are obtained from third party information.
Exploits (1)
This is a vulnerability writeup describing multiple XSS vulnerabilities in I-Escorts products due to improper input sanitization. It provides an example URL but does not include functional exploit code.