CVE-2014-9916
MEDIUMBilboplanet 2.0 - Cross-Site Scripting via Tribe Name or Tags Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-9916. PoCs published by Vivek N.
AI-analyzed exploit summary This is a writeup describing multiple stored XSS vulnerabilities in the Bilboplanet application version 2.0. It outlines three specific endpoints and parameters where XSS payloads can be injected, but does not include actual exploit code or payloads.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tribe_name or (2) tags parameter in a tribes page request to user/ or the (3) user_id or (4) fullname parameter to signup.php.
Exploits (1)
This is a writeup describing multiple stored XSS vulnerabilities in the Bilboplanet application version 2.0. It outlines three specific endpoints and parameters where XSS payloads can be injected, but does not include actual exploit code or payloads.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N