CVE-2010-1091

phpMySite - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in contact.php in phpMySite allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) city, (3) email, (4) state, and (5) message parameters.

Exploits (1)

exploitdb WORKING POC
by Crux · textwebappsphp
https://www.exploit-db.com/exploits/11588

Scores

EPSS 0.0135
EPSS Percentile 79.9%

Classification

CWE
CWE-79
Status published

Affected Products (2)

phpmysite/phpmysite
n/a/n/a

Timeline

Published Mar 24, 2010
Tracked Since Feb 18, 2026