CVE-2011-5041
Pulsecms Pulse Cms - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) d parameter in a blocks action and (2) post_id parameter in an edit-post action to index.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Avram Marius · textwebappsphp
https://www.exploit-db.com/exploits/36447
Scores
EPSS
0.0046
EPSS Percentile
63.7%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
pulsecms/pulse_cms
n/a/n/a
Timeline
Published
Dec 30, 2011
Tracked Since
Feb 18, 2026