Description
Multiple cross-site scripting (XSS) vulnerabilities in PaysiteReviewCMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to search.php or the (2) image parameter to image.php.
Exploits (2)
exploitdb
WRITEUP
VERIFIED
by Valentin Hoebel · textwebappsphp
https://www.exploit-db.com/exploits/34619
exploitdb
WRITEUP
VERIFIED
by Valentin Hoebel · textwebappsphp
https://www.exploit-db.com/exploits/34620
References (4)
Core 4
Core References
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/8444
Exploit x_refsource_misc
http://www.xenuser.org/documents/security/mechbunny_paysitereviewcms_xss.txt
Exploit x_refsource_misc
http://packetstormsecurity.org/1009-exploits/mechbunnypsr-xss.txt
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/41431
Scores
EPSS
0.0112
EPSS Percentile
78.5%
Details
CWE
CWE-79
Status
published
Products (1)
mechbunny/paysitereviewcms
1.1
Published
Oct 08, 2011
Tracked Since
Feb 18, 2026