Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-2457. PoCs published by Sangteamtham.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in K-Search. The SQLi exploit uses a UNION-based attack to extract database information, while the XSS exploit injects malicious JavaScript via the 'term' parameter.
Description
Cross-site scripting (XSS) vulnerability in index.php in K-Search allows remote attackers to inject arbitrary web script or HTML via the term parameter.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in K-Search. The SQLi exploit uses a UNION-based attack to extract database information, while the XSS exploit injects malicious JavaScript via the 'term' parameter.