CVE-2009-4983
Silurus Classifieds 1.0 - Cross-Site Scripting via ID and Keywords Parameters
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2009-4983. PoCs published by Moudi.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Silurus System 1.0 by injecting a malicious script into the 'ID' parameter of 'wcategory.php'. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) category.php and (2) wcategory.php, and the (3) keywords parameter to search.php.
Exploits (3)
This exploit demonstrates a reflected XSS vulnerability in Silurus System 1.0 by injecting a malicious script into the 'ID' parameter of 'wcategory.php'. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Silurus System 1.0 by injecting a malicious script into the 'keywords' parameter of the search.php page. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookie-based authentication credentials.
This exploit demonstrates a reflected XSS vulnerability in Silurus System 1.0 by injecting a malicious script into the 'ID' parameter of category.php, which executes arbitrary JavaScript in the context of the affected site.