CVE-2012-4242
NUCLEIMF Gig Calendar 0.9.2 - Cross-Site Scripting via Query String
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-4242. PoCs published by Chris Cooper. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in the MF Gig Calendar WordPress plugin by injecting a script tag via the 'page_id' parameter. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar page.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in the MF Gig Calendar WordPress plugin by injecting a script tag via the 'page_id' parameter. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.