CVE-2009-4983

Snowhall Silurus System - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) category.php and (2) wcategory.php, and the (3) keywords parameter to search.php.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34643
exploitdb WORKING POC VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34644
exploitdb WORKING POC VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34645

Scores

EPSS 0.0018
EPSS Percentile 39.2%

Classification

CWE
CWE-79
Status published

Affected Products (2)

snowhall/silurus_system
n/a/n/a

Timeline

Published Aug 25, 2010
Tracked Since Feb 18, 2026