Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-4772. PoCs published by LordTittiS.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in S-CMS 2.5, including Full Path Disclosure (FPD), SQL Injection (SQLi), and Cross-Site Scripting (XSS) via the 'id' parameter in viewforum.php. The provided URLs showcase direct exploitation vectors for these vulnerabilities.
Description
Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS 2.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter to viewforum.php.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in S-CMS 2.5, including Full Path Disclosure (FPD), SQL Injection (SQLi), and Cross-Site Scripting (XSS) via the 'id' parameter in viewforum.php. The provided URLs showcase direct exploitation vectors for these vulnerabilities.