CVE-2012-5899
SAMEDIA LandShop 0.9.2 - Cross-Site Scripting via OTR_HEADS Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-5899. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary The document describes multiple vulnerabilities in Landshop v0.9.2, including SQL injection and persistent XSS. It provides proof-of-concept URLs for SQL injection but lacks executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the OTR_HEADS[] parameter in an edit action. NOTE: some of these details are obtained from third party information.
Exploits (1)
The document describes multiple vulnerabilities in Landshop v0.9.2, including SQL injection and persistent XSS. It provides proof-of-concept URLs for SQL injection but lacks executable exploit code.