CVE-2009-4926

Online Contact Manager 3.0 - Cross-Site Scripting via showGroup and id Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 5 public exploits for CVE-2009-4926. PoCs published by Vrs-hCk.

AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Online Contact Manager 3.0, where user-supplied input is not properly sanitized. The example demonstrates a simple XSS payload injected via the 'id' parameter in the URL.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) showGroup parameter to (a) index.php and the (2) id parameter to (b) view.php, (c) email.php, (d) edit.php, and (e) delete.php.

Exploits (5)

exploitdb WRITEUP VERIFIED
by Vrs-hCk · textwebappsphp
https://www.exploit-db.com/exploits/32934

The provided text describes a cross-site scripting (XSS) vulnerability in Online Contact Manager 3.0, where user-supplied input is not properly sanitized. The example demonstrates a simple XSS payload injected via the 'id' parameter in the URL.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Online Contact Manager 3.0
No auth needed
Prerequisites: Access to the vulnerable application URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Vrs-hCk · textwebappsphp
https://www.exploit-db.com/exploits/32933

This exploit demonstrates a cross-site scripting (XSS) vulnerability in Online Contact Manager 3.0 by injecting a script tag into the 'showGroup' parameter. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Online Contact Manager 3.0
No auth needed
Prerequisites: Access to the vulnerable web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Vrs-hCk · textwebappsphp
https://www.exploit-db.com/exploits/32935

The provided text describes a cross-site scripting (XSS) vulnerability in Online Contact Manager 3.0, where user-supplied input is not properly sanitized. The example demonstrates a reflected XSS attack via the 'id' parameter in 'email.php'.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Online Contact Manager 3.0
No auth needed
Prerequisites: Access to the vulnerable web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Vrs-hCk · textwebappsphp
https://www.exploit-db.com/exploits/32936

The provided text describes a cross-site scripting (XSS) vulnerability in Online Contact Manager 3.0, where user-supplied input is not properly sanitized. The example demonstrates a simple XSS payload injected via the 'id' parameter in edit.php.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Online Contact Manager 3.0
No auth needed
Prerequisites: Access to the vulnerable web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Vrs-hCk · textwebappsphp
https://www.exploit-db.com/exploits/32937

The provided text describes a cross-site scripting (XSS) vulnerability in Online Contact Manager 3.0, where user-supplied input is not properly sanitized. The example demonstrates a reflected XSS attack via the 'id' parameter in delete.php.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Online Contact Manager 3.0
No auth needed
Prerequisites: Access to the vulnerable web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34626
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34826

Scores

EPSS 0.0148
EPSS Percentile 70.5%

Details

CWE
CWE-79
Status published
Products (1)
esoftpro/online_contact_manager 3.0
Published Jul 12, 2010
Tracked Since Feb 18, 2026