CVE-2010-2675
TSOKA:CMS 1.1, 1.9, 2.0 - Cross-Site Scripting via id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2675. PoCs published by d3v1l.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in TSOKA:CMS versions 1.1, 1.9, and 2.0. It provides example URLs to exploit the vulnerabilities, including a UNION-based SQL injection to extract database information.
Description
Cross-site scripting (XSS) vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in an articolo action.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in TSOKA:CMS versions 1.1, 1.9, and 2.0. It provides example URLs to exploit the vulnerabilities, including a UNION-based SQL injection to extract database information.