CVE-2010-1048
Uiga Business Portal - Stored Cross-Site Scripting via Comment Box Textcomment Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1048. PoCs published by Sioma Labs.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Uiga Business Portal. The SQLi allows unauthorized data extraction from user and admin tables, while the XSS can be triggered via the comment box.
Description
Cross-site scripting (XSS) vulnerability in blog/index.php in Uiga Business Portal allows remote attackers to inject arbitrary web script or HTML via the textcomment parameter (aka the Comment Box) in a noentryid action. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Uiga Business Portal. The SQLi allows unauthorized data extraction from user and admin tables, while the XSS can be triggered via the comment box.