CVE-2010-2464
RSComments (com_rscomments) 1.0.0 Rev 2 - Cross-Site Scripting via Website and Name Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2464. PoCs published by jdc.
AI-analyzed exploit summary This exploit demonstrates persistent XSS vulnerabilities in Joomla Component RSComments 1.0.0. It provides payloads for the 'Name' and 'Website' fields that execute JavaScript in the backend when triggered by mouseover events.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.
Exploits (1)
This exploit demonstrates persistent XSS vulnerabilities in Joomla Component RSComments 1.0.0. It provides payloads for the 'Name' and 'Website' fields that execute JavaScript in the backend when triggered by mouseover events.