CVE-2010-4873
WeBid 0.8.5 P1 - Cross-Site Scripting via confirm.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-4873. PoCs published by John Leitch.
AI-analyzed exploit summary The provided text describes multiple input-validation vulnerabilities in WeBid, including a local file inclusion (LFI) and cross-site scripting (XSS) vulnerability. It includes example URLs demonstrating the exploits but does not contain executable code.
Description
Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Exploits (1)
The provided text describes multiple input-validation vulnerabilities in WeBid, including a local file inclusion (LFI) and cross-site scripting (XSS) vulnerability. It includes example URLs demonstrating the exploits but does not contain executable code.