Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-4609. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in HTML-EDIT CMS 3.1.8 via unsanitized user input in the 'nuser' and 'error' parameters. It includes PoC forms and URLs to trigger these vulnerabilities.
Description
SQL injection vulnerability in index.php in Html-edit CMS 3.1.8 allows remote attackers to execute arbitrary SQL commands via the nuser parameter in a registrate action.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in HTML-EDIT CMS 3.1.8 via unsanitized user input in the 'nuser' and 'error' parameters. It includes PoC forms and URLs to trigger these vulnerabilities.