Cross-Site Scripting Vulnerability in CruxCMS by Crux Software
CVE-2008-0700

Currently unrated

Key Information:

Status
Vendor
CVE Published:
12 February 2008

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2008-0700?

A cross-site scripting (XSS) vulnerability exists in the search.php file of CruxCMS version 3.0. This flaw allows remote attackers to inject arbitrary web script or HTML through the 'search' parameter, potentially compromising the security of the web application and its users. The origin of this information remains unverified, being compiled from third-party sources.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • Vulnerability Reserved

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

.