CVE-2010-4611
html-edit CMS 3.1.8 - Exposure of Sensitive Information via Direct Request to Core Files
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-4611. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in HTML-EDIT CMS 3.1.8 via unsanitized user input in the 'nuser' and 'error' parameters. It includes PoC forms and URLs to trigger these vulnerabilities.
Description
Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2) menu.php in includes/core_files and (3) extensions/login/frontend/pages/antihacker.php, which reveals the installation path in an error message.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in HTML-EDIT CMS 3.1.8 via unsanitized user input in the 'nuser' and 'error' parameters. It includes PoC forms and URLs to trigger these vulnerabilities.