CVE-2010-5035
iScripts eSwap 2.0 - Cross-Site Scripting via txtHomeSearch Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-5035. PoCs published by Sid3^effects.
AI-analyzed exploit summary The document describes SQL injection and XSS vulnerabilities in iScripts eSwap v2.0, providing attack patterns and demo URLs but no functional exploit code. It includes technical details about the vulnerabilities and their locations.
Description
Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary web script or HTML via the txtHomeSearch parameter (aka the search field). NOTE: some of these details are obtained from third party information.
Exploits (1)
The document describes SQL injection and XSS vulnerabilities in iScripts eSwap v2.0, providing attack patterns and demo URLs but no functional exploit code. It includes technical details about the vulnerabilities and their locations.