CVE-2009-4984
Accessories Me PHP Affiliate Script 1.4 - Cross-Site Scripting via Keywords or SearchIndex Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4984. PoCs published by Moudi.
AI-analyzed exploit summary The exploit demonstrates XSS and blind SQL injection vulnerabilities in AccessoriesMe PHP Affiliate Script v1.4. It provides functional PoC URLs for both XSS (via 'Keywords' and 'SearchIndex' parameters) and blind SQLi (via 'Go' parameter in browse.php).
Description
Multiple cross-site scripting (XSS) vulnerabilities in Accessories Me PHP Affiliate Script 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Keywords parameter to search.php and (2) SearchIndex parameter to browse.php.
Exploits (1)
The exploit demonstrates XSS and blind SQL injection vulnerabilities in AccessoriesMe PHP Affiliate Script v1.4. It provides functional PoC URLs for both XSS (via 'Keywords' and 'SearchIndex' parameters) and blind SQLi (via 'Go' parameter in browse.php).