CVE-2009-4934
Online Photo Pro 2.0 - Cross-Site Scripting via Section Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4934. PoCs published by Vrs-hCk.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Online Photo Pro 2.0, where arbitrary script code can be executed via the 'section' parameter in the URL. The example demonstrates a simple alert-based XSS payload.
Description
Cross-site scripting (XSS) vulnerability in index.php in Online Photo Pro 2.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in Online Photo Pro 2.0, where arbitrary script code can be executed via the 'section' parameter in the URL. The example demonstrates a simple alert-based XSS payload.