CVE-2011-5185
Online Subtitles Workshop < 2.0 - Cross-Site Scripting via Comment Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-5185. PoCs published by M.Jock3R.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Online Subtitles Workshop's video_comments.php file, where user input is directly rendered without sanitization. Attackers can inject arbitrary HTML or JavaScript code via video comments.
Description
Cross-site scripting (XSS) vulnerability in video_comments.php in Online Subtitles Workshop before 2.0 rev 131 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Online Subtitles Workshop's video_comments.php file, where user input is directly rendered without sanitization. Attackers can inject arbitrary HTML or JavaScript code via video comments.