CVE-2010-2917
AJ Square AJ Article 3.0 - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2917. PoCs published by Sid3^effects.
AI-analyzed exploit summary This is a writeup describing a persistent XSS vulnerability in AJArticle v3. The vulnerability allows attackers to inject malicious scripts into the profile section or article submission fields, which are then executed when other users view the affected pages.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) emailid, (2) fname, (3) lname, (4) company, (5) address1, (6) address2, (7) city, (8) state, (9) zipcode, (10) phone, and (11) fax parameters in an update action. NOTE: some of these details are obtained from third party information.
Exploits (1)
This is a writeup describing a persistent XSS vulnerability in AJArticle v3. The vulnerability allows attackers to inject malicious scripts into the profile section or article submission fields, which are then executed when other users view the affected pages.