CVE-2014-9917
MEDIUMBilboplanet 2.0 - Stored Cross-Site Scripting via Tags Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-9917. PoCs published by Vivek N.
AI-analyzed exploit summary This is a writeup describing multiple stored XSS vulnerabilities in the Bilboplanet application version 2.0. It outlines three specific endpoints and parameters where XSS payloads can be injected, but does not include actual exploit code or payloads.
Description
An issue was discovered in Bilboplanet 2.0. There is a stored XSS vulnerability when adding a tag via the user/?page=tribes tags parameter.
Exploits (1)
This is a writeup describing multiple stored XSS vulnerabilities in the Bilboplanet application version 2.0. It outlines three specific endpoints and parameters where XSS payloads can be injected, but does not include actual exploit code or payloads.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N