CVE-2014-8469
moxi9 phpfox < 3.7.6 - Cross-Site Scripting via User-Agent Header
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-8469. PoCs published by spyk2r.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in PHPFox's AdminCP by injecting malicious JavaScript via the User-Agent header. The payload is stored in the database and executed when an admin views the 'Online Guests/Boots' section.
Description
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in PHPFox's AdminCP by injecting malicious JavaScript via the User-Agent header. The payload is stored in the database and executed when an admin views the 'Online Guests/Boots' section.