CVE-2010-1997
Saurus CMS 4.7.0 - Authenticated Stored Cross-Site Scripting via pealkiri Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1997. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Saurus CMS 4.7.0 Community Edition by injecting a malicious script into the 'pealkiri' parameter, which executes when the form is submitted. The PoC uses a hidden form with JavaScript auto-submission to trigger the vulnerability.
Description
Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "Article list" edit privileges, to inject arbitrary web script or HTML via the pealkiri parameter.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Saurus CMS 4.7.0 Community Edition by injecting a malicious script into the 'pealkiri' parameter, which executes when the form is submitted. The PoC uses a hidden form with JavaScript auto-submission to trigger the vulnerability.