CVE-2010-2256
Pay Per Minute Video Chat Script 2.0-2.1 - Cross-Site Scripting via id Parameter or model Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2256. PoCs published by R3d-D3V!L.
AI-analyzed exploit summary This exploit demonstrates XSS and SQL injection vulnerabilities in Pay Per Minute Video Chat Script V 2.1. It includes proof-of-concept URLs for XSS and mentions SQL injection without a working exploit.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to videos.php.
Exploits (1)
This exploit demonstrates XSS and SQL injection vulnerabilities in Pay Per Minute Video Chat Script V 2.1. It includes proof-of-concept URLs for XSS and mentions SQL injection without a working exploit.