Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-0695. PoCs published by Red-D3v1L.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Basic-CMS by injecting a script tag via the 'nav_id' parameter. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Basic-CMS by injecting a script tag via the 'nav_id' parameter. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.