18422exploit
http://www.exploit-db.com/exploits/18422 CVE-2012-5226
Peel Shopping 2.8/ 2.9 - Cross-Site Scripting / SQL Injections
Record summary
CVE-2012-5226 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Peel SHOPPING 2.8 and 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) motclef parameter to achat/recherche.php or (2) PATH_INFO to index.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPeel Shopping 2.8/ 2.9 - Cross-Site Scripting / SQL InjectionsExploitDB exploitby Cyber-CrystalNot analyzed1 file
References
451700vdb entry
http://www.securityfocus.com/bid/51700 peelshopping-multiple-xss(72765)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/72765 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-5226