Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-1711. PoCs published by JosS.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in SIESTTA 2.0 via the 'idioma' parameter in login.php and a Cross-Site Scripting (XSS) vulnerability in carga_foto_al.php via the 'usuario' parameter. Both vulnerabilities require register_globals to be enabled.
Description
Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the usuario parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in SIESTTA 2.0 via the 'idioma' parameter in login.php and a Cross-Site Scripting (XSS) vulnerability in carga_foto_al.php via the 'usuario' parameter. Both vulnerabilities require register_globals to be enabled.